Описание
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.
Ссылки
- Release NotesThird Party Advisory
- MitigationThird Party Advisory
- Release NotesThird Party Advisory
- MitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pingcap:tidb:5.3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 22%
0.00072
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
EPSS
Процентиль: 22%
0.00072
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-287