PT-2023-9595 · Mysql Server+1 · Mysql Connectors+1

Published

2023-12-07

·

Updated

2026-04-10

·

CVE-2024-21272

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 9.0.0 and prior
Description The issue is related to a lack of authentication for a critical function in the Connector/Python component of MySQL Connectors, allowing a low-privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks can result in the takeover of MySQL Connectors.
Recommendations For versions 9.0.0 and prior, update to a version that includes a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-08608
CVE-2024-21272
GHSA-HGJP-83M4-H4FJ
OPENSUSE-SU-2024:0351-1
OPENSUSE-SU-2024:14421-1

Affected Products

Mysql Connectors
Red Os