PT-2022-24818 · Mariadb+1 · Mariadb+1

Tarihub

·

Published

2022-09-26

·

Updated

2024-08-21

·

CVE-2022-39219

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Bifrost versions 1.8.6-release and prior
Description Bifrost is a middleware package that synchronizes MySQL/MariaDB binlog data to other types of databases. The issue allows group members with only read permissions to write requests when they are normally forbidden from doing so, due to an authentication bypass when using HTTP basic authentication.
Recommendations For versions 1.8.6-release and prior, update to version 1.8.7-release to resolve the issue. As a temporary workaround, consider disabling HTTP basic authentication until a patch is applied. Restrict access to sensitive data to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2022-39219
GHSA-P6FH-XC6R-G5HW
GO-2022-1023

Affected Products

Mariadb
Mysql Server