Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15180

Опубликовано: 06 окт. 2020
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in wsrep_sst_method allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

Отчет

galera packages as shipped with Red Hat Enterprise Linux and Red Hat Software Collections are not affected because they do not contain the vulnerable mysql-wsrep component.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbNot affected
Red Hat OpenStack Platform 10 (Newton)galeraNot affected
Red Hat OpenStack Platform 13 (Queens)galeraNot affected
Red Hat Software Collectionsrh-mariadb102-galeraNot affected
Red Hat Software Collectionsrh-mariadb102-mariadbWill not fix
Red Hat Enterprise Linux 8mariadbFixedRHSA-2020:550015.12.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsmariadbFixedRHSA-2020:566322.12.2020
Red Hat Enterprise Linux 8.1 Extended Update SupportmariadbFixedRHSA-2020:566522.12.2020
Red Hat Enterprise Linux 8.2 Extended Update SupportmariadbFixedRHSA-2020:565422.12.2020
Red Hat OpenStack Platform 10.0 (Newton)mariadb-galeraFixedRHSA-2020:537908.12.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-96
https://bugzilla.redhat.com/show_bug.cgi?id=1894919mariadb: Insufficient SST method name check leading to code injection in mysql-wsrep

EPSS

Процентиль: 89%
0.04602
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
ubuntu
около 4 лет назад

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

CVSS3: 9
nvd
около 4 лет назад

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

CVSS3: 9
debian
около 4 лет назад

A flaw was found in the mysql-wsrep component of mariadb. Lack of inpu ...

CVSS3: 9
fstec
больше 4 лет назад

Уязвимость компонента mysql-wsrep СУБД MariaDB, связанная с ошибками обработки входных данных при выполнении синтаксического анализа кода, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
больше 4 лет назад

Security update for mariadb

EPSS

Процентиль: 89%
0.04602
Низкий

9 Critical

CVSS3