PT-2024-12816 · Mariadb Foundation+1 · Mariadb+1
King Cope
·
Published
2023-08-07
·
Updated
2025-07-11
·
CVE-2023-39593
CVSS v2.0
5.7
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MariaDB version 10.5
Description
Insecure permissions in the
sys exec function allow authenticated attackers to execute arbitrary commands with elevated privileges. This issue is disputed by the MariaDB Foundation because no privilege boundary is crossed.Recommendations
For MariaDB version 10.5, consider disabling the
sys exec function as a temporary workaround until a patch is available. Restrict access to the sys exec function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Check for Exceptional Conditions
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mariadb
Red Os