Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10997

Опубликовано: 27 апр. 2020
Источник: debian
EPSS Низкий

Описание

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
percona-xtrabackupnot-affectedpackage

Примечания

  • https://jira.percona.com/browse/PXB-2142

  • Introduced in: https://github.com/percona/percona-xtrabackup/commit/0b38ffc0f30f1b6d3ff7ed0f9cb3ab31a2ccad13 (percona-xtrabackup-2.4.11)

  • https://www.percona.com/blog/2020/04/16/cve-2020-10997-percona-xtrabackup-information-disclosure-of-command-line-arguments/

EPSS

Процентиль: 51%
0.00284
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.

CVSS3: 6.5
nvd
почти 6 лет назад

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.

github
больше 3 лет назад

Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.

suse-cvrf
около 3 лет назад

Security update for xtrabackup

EPSS

Процентиль: 51%
0.00284
Низкий