Описание
environment injection via wsrep bootstrap in the mariadb.service file
Impact
It was possible for a user with FILE privileges and a secure-file-priv system variable configuration that allows writes to /run/mysqld, to create the environment file /run/mysqld/wsrep-new-cluster that the mariadb service will use on the next restart.
Patches
Fixed in 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, 13.0.2.
Workarounds
Make sure secure-file-priv does not allow writes to /run/mysqld and revoke FILE privilege from all accounts that do not need it.
References
https://jira.mariadb.org/browse/MDEV-40629
Credits
Vincent55 Yang via the Webpros (cPanel/Plesk) security team
Пакеты
mariadb
>=10.6.1, <=10.6.27
10.6.28
mariadb
>=10.11.1, <=10.11.18
10.11.19
mariadb
>=11.4.1, <=11.4.12
11.4.13
mariadb
>=11.8.1, <=11.8.8
11.8.9
mariadb
>=12.3.1, <=12.3.2
12.3.3
mariadb
13.0.1
13.0.2
8.4 High
CVSS3
Дефекты
8.4 High
CVSS3