Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p3m-4x7c-p4pw

Опубликовано: 02 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

unsafe parameter handing in wsrep_notify_cmd

Impact

MariaDB server, with wsrep_notify_cmd enabled would execute shell commands embedded in the name of the joiner node.

Patches

Fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, 12.3.2.

Workarounds

Anyone who cannot upgrade now should disable wsrep_notify_cmd.

References

https://jira.mariadb.org/browse/MDEV-39721

Credits

letchu_pkt

Пакеты

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.6.1, <=10.6.26

10.6.27

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.11.1, <=10.11.17

10.11.18

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.4.1, <=11.4.11

11.4.12

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.8.1, <=11.8.7

11.8.8

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

12.3.1

12.3.2

EPSS

Процентиль: 70%
0.01415
Низкий

10 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 10
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 9
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVSS3: 10
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. Versions ...

oracle-oval
29 дней назад

ELSA-2026-33482: mariadb:10.11 security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 70%
0.01415
Низкий

10 Critical

CVSS3

Дефекты

CWE-78