Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m85-2x26-36rf

Опубликовано: 07 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

database privilege escalation via user / role name collision in the acl cache

Impact

An attacker with the CREATE USER privilege can create a localhost user with the name of the existing privileged role or a role with the name of the existing privileged localhost user. If the database level privileges for the original role or user account were cached, the attacker exercise them due to the acl cache collision.

Patches

Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.

Workarounds

CREATE USER is a high privileged administrative operation, if only high privileged users have it, they won't have a higher-privileged account to escalate to. In most installation this is already the case.

References

https://jira.mariadb.org/browse/MDEV-40541

Credit

Andrew James Gonzalez

Пакеты

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.6.1, <=10.6.27

10.6.28

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.11.1, <=10.11.18

10.11.19

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.4.1, <=11.4.12

11.4.13

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.8.1, <=11.8.8

11.8.9

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=12.3.1, <=12.3.2

12.3.3

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

13.0.1

13.0.2

6.4 Medium

CVSS3

Дефекты

CWE-706
CWE-863

6.4 Medium

CVSS3

Дефекты

CWE-706
CWE-863