Описание
database privilege escalation via user / role name collision in the acl cache
Impact
An attacker with the CREATE USER privilege can create a localhost user with the name of the existing privileged role or a role with the name of the existing privileged localhost user. If the database level privileges for the original role or user account were cached, the attacker exercise them due to the acl cache collision.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
CREATE USER is a high privileged administrative operation, if only high privileged users have it, they won't have a higher-privileged account to escalate to. In most installation this is already the case.
References
https://jira.mariadb.org/browse/MDEV-40541
Credit
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2
6.4 Medium
CVSS3
Дефекты
6.4 Medium
CVSS3