Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22xq-vq3f-87x2

Опубликовано: 18 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Authorization bypass in role-based routine-level privilege check exposes stored routine definitions

Impact

A user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege.

Patches

Fixed in 11.4.11, 11.8.7, 12.3. 2

References

https://jira.mariadb.org/browse/MDEV-39288

Credits

Aisle Research

Пакеты

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.4.1, <=11.4.10

11.4.11

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.8.1, <=11.8.6

11.8.7

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

12.3.1

12.3.2

EPSS

Процентиль: 6%
0.00161
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 4.3
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 4.3
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 4.3
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From ver ...

rocky
26 дней назад

Important: mariadb:11.8 security, bug fix, and enhancement update

EPSS

Процентиль: 6%
0.00161
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863