Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g76j-4cxx-23h9

Опубликовано: 20 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Пакеты

Наименование

mysql:mysql-connector-java

maven
Затронутые версииВерсия исправления

<= 8.0.27

8.0.28

EPSS

Процентиль: 73%
0.00754
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-280

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
redhat
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
nvd
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 6.6
debian
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...

EPSS

Процентиль: 73%
0.00754
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-280