PT-2025-4270 · Mysql Server · Mysql Connectors

Weibin Shi

·

Published

2025-01-21

·

Updated

2025-01-27

·

CVE-2025-21548

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 9.1.0 and prior
Description The issue allows a high-privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. This can result in unauthorized creation, deletion, or modification of critical data or all accessible data, as well as unauthorized read access to a subset of accessible data. Additionally, it can cause a hang or frequently repeatable crash of MySQL Connectors.
Recommendations For versions 9.1.0 and prior, update to a version later than 9.1.0 to resolve the issue. At the moment, there is no information about other specific mitigation measures for this vulnerability.

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01296
CVE-2025-21548

Affected Products

Mysql Connectors