PT-2022-24818 · Mariadb+1 · Mariadb+1
Tarihub
·
Published
2022-09-26
·
Updated
2024-08-21
·
CVE-2022-39219
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Bifrost versions 1.8.6-release and prior
Description
Bifrost is a middleware package that synchronizes MySQL/MariaDB binlog data to other types of databases. The issue allows group members with only read permissions to write requests when they are normally forbidden from doing so, due to an authentication bypass when using HTTP basic authentication.
Recommendations
For versions 1.8.6-release and prior, update to version 1.8.7-release to resolve the issue. As a temporary workaround, consider disabling HTTP basic authentication until a patch is applied. Restrict access to sensitive data to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mariadb
Mysql Server