Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmxm-6wxc-3xqf

Опубликовано: 22 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache ShardingSphere-Proxy Incomplete Cleanup vulnerability

Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.

Пакеты

Наименование

org.apache.shardingsphere:shardingsphere-proxy

maven
Затронутые версииВерсия исправления

< 5.3.0

5.3.0

EPSS

Процентиль: 32%
0.00122
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.

EPSS

Процентиль: 32%
0.00122
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-459