Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c2c-wp2q-q5vx

Опубликовано: 09 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.

EPSS

Процентиль: 19%
0.00059
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-696

Связанные уязвимости

CVSS3: 4.9
ubuntu
3 месяца назад

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.

CVSS3: 4.9
redhat
3 месяца назад

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.

CVSS3: 4.9
nvd
3 месяца назад

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.

CVSS3: 4.9
debian
3 месяца назад

MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 1 ...

CVSS3: 4.9
redos
около 2 месяцев назад

Уязвимость mariadb

EPSS

Процентиль: 19%
0.00059
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-696