Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24050

Опубликовано: 18 фев. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mariadbOut of support scope
Red Hat JBoss Core ServicesmariadbNot affected
Red Hat OpenStack Platform 13 (Queens)mariadbOut of support scope
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:582602.08.2022
Red Hat Enterprise Linux 8mariadbFixedRHSA-2022:644313.09.2022
Red Hat Enterprise Linux 9mariadbFixedRHSA-2022:594809.08.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb105-mariadbFixedRHSA-2022:575928.07.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-mariadb103-mariadbFixedRHSA-2022:630601.09.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1173
https://bugzilla.redhat.com/show_bug.cgi?id=2069833mariadb: lack of validating the existence of an object prior to performing operations on the object

EPSS

Процентиль: 29%
0.00103
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

CVSS3: 7.8
nvd
почти 4 года назад

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

CVSS3: 7.8
msrc
почти 4 года назад

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

CVSS3: 7.8
debian
почти 4 года назад

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vul ...

CVSS3: 7.8
github
почти 4 года назад

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

EPSS

Процентиль: 29%
0.00103
Низкий

7.8 High

CVSS3