PT-2023-2668 · Mysql Server+2 · Mysql Connectors+2

Published

2023-04-18

·

Updated

2024-08-28

·

CVE-2023-21971

CVSS v2.0

5.8

Medium

VectorAV:N/AC:H/Au:M/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 8.0.32 and prior
Description The vulnerability exists due to insufficient input validation in the Connector/J component of the MySQL Connectors product. A difficult to exploit vulnerability allows a high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Connectors, as well as unauthorized update, insert, or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data.
Recommendations For versions 8.0.32 and prior, update to a version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02508
CVE-2023-21971
OPENSUSE-SU-2023_2979-1
OPENSUSE-SU-2024:12927-1
SUSE-SU-2023:2241-1
SUSE-SU-2023:2979-1

Affected Products

Mysql Connectors
Red Os
Suse