PT-2023-4394 · Mariadb · Mariadb Maxscale

Massimo

·

Published

2023-07-25

·

Updated

2023-08-22

·

CVE-2023-40354

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MariaDB MaxScale versions prior to 2.5.28 MariaDB MaxScale versions prior to 6.4.9 MariaDB MaxScale versions prior to 22.08.8 MariaDB MaxScale versions prior to 23.02.3
Description An issue was discovered in MariaDB MaxScale where a user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. This issue is related to the lack of encryption measures for data in the /var/lib/maxscale/maxscale.cnf.d component of the MariaDB MaxScale database proxy server. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 2.5.28, update to version 2.5.28 or later. For versions prior to 6.4.9, update to version 6.4.9 or later. For versions prior to 22.08.8, update to version 22.08.8 or later. For versions prior to 23.02.3, update to version 23.02.3 or later. As a temporary workaround, consider restricting access to the /var/lib/maxscale/maxscale.cnf.d directory to minimize the risk of exploitation.

Fix

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-04739
CVE-2023-40354

Affected Products

Mariadb Maxscale