Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-2471

Опубликовано: 20 окт. 2021
Источник: redhat
CVSS3: 7.4
EPSS Средний

Описание

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).

MySQL Connector/J has no security check when external general entities are included in XML sources, consequently, there exists an XML External Entity(XXE) vulnerability. A successful attack can access critical data and gain full control/access to all MySQL Connectors' accessible data without any authorization.

Отчет

In OpenShift Container Platform (OCP), the Presto component is part of the OCP Metering stack and it ships the vulnerable version of the MySQL Connector/J package. Since the release of OCP 4.6, the Metering product has been deprecated and is removed from OCP starting from 4.9 version [1], hence the affected component is marked as wontfix. [1] https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html#ocp-4-9-deprecated-removed-features

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Debezium 1mysql-connector-javaAffected
Red Hat build of Quarkusmysql-connector-javaAffected
Red Hat Enterprise Linux 6mysql-connector-javaOut of support scope
Red Hat Enterprise Linux 7mysql-connector-javaOut of support scope
Red Hat Integration Camel K 1mysql-connector-javaAffected
Red Hat JBoss Data Virtualization 6mysql-connector-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 6mysql-connector-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 7mysql-connector-javaWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packmysql-connector-javaOut of support scope
Red Hat JBoss Fuse 6mysql-connector-javaOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2020583mysql-connector-java: unauthorized access to critical

EPSS

Процентиль: 98%
0.65138
Средний

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).

CVSS3: 5.9
nvd
больше 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).

CVSS3: 5.9
msrc
больше 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).

CVSS3: 5.9
debian
больше 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...

suse-cvrf
почти 4 года назад

Security update for mysql-connector-java

EPSS

Процентиль: 98%
0.65138
Средний

7.4 High

CVSS3