Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr59-q2m8-w439

Опубликовано: 18 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

Insecure permissions in the sys_exec function of Oracle MYSQL MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.

Insecure permissions in the sys_exec function of Oracle MYSQL MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.

EPSS

Процентиль: 62%
0.00431
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 1 года назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.5
redhat
около 1 года назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.6
nvd
около 1 года назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.6
debian
около 1 года назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows ...

CVSS3: 5.6
fstec
больше 2 лет назад

Уязвимость функции sys_exec() системы управления базами данных MariaDB, позволяющая нарушителю выполнять произвольные команды с повышенными привилегиями

EPSS

Процентиль: 62%
0.00431
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-94