PT-2022-20025 · Tidb · Tidb

Published

2022-11-04

·

Updated

2022-11-05

·

CVE-2022-3023

CVSS v3.1

4.2

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TiDB versions prior to 6.4.0 TiDB versions prior to 6.1.3
Description The issue concerns the use of an externally-controlled format string and data source name injection in the TiDB server. Specifically, the database name for generating and inserting data into a database does not properly sanitize user input, which can lead to arbitrary file reads.
Recommendations For versions prior to 6.4.0, update to version 6.4.0 or later. For versions prior to 6.1.3, update to version 6.1.3 or later.

Exploit

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2022-3023
GHSA-7FXJ-FR3V-R9GJ

Affected Products

Tidb