Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-667j-m53j-wpmc

Опубликовано: 18 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

FILE privilege was not checked for subqueries in the FROM clause

Impact

MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries.

Patches

Fixed in 10.6.26, 10.11.17, 11.4.11, 11.8.7, 12.3.2.

Workarounds

Filesystem privileges and --secure-file-priv option still apply and should always be used to limit locations that the server can write to.

References

https://jira.mariadb.org/browse/MDEV-39493

Credits

Tomer Fichman

Пакеты

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.6.1, <=10.6.25

10.6.26

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=10.11.1, <=10.11.16

10.11.17

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.4.1, <=11.4.10

11.4.11

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

>=11.8.1, <=11.8.6

11.8.7

Наименование

mariadb

mariadb
Затронутые версииВерсия исправления

12.3.1

12.3.2

EPSS

Процентиль: 32%
0.00399
Низкий

5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5
ubuntu
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 8.1
redhat
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 5
nvd
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.

CVSS3: 5
debian
около 2 месяцев назад

MariaDB server is a community developed fork of MySQL server. From ver ...

rocky
26 дней назад

Important: mariadb:10.11 security, bug fix, and enhancement update

EPSS

Процентиль: 32%
0.00399
Низкий

5 Medium

CVSS3

Дефекты

CWE-863