Описание
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
A flaw was found in MariaDB. An authenticated database user can exploit this vulnerability by invoking SQL statements prefixed with double-hyphen (—) or hash (#) style comments. When the server audit plugin is enabled with specific event filtering, these statements are not logged. This oversight can lead to critical database operations bypassing audit logging, hindering security monitoring and compliance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | mariadb10.11 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | mariadb11.8 | Fix deferred | ||
| Red Hat Enterprise Linux 7 | mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb:10.11/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb:10.3/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb:10.5/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mariadb-devel:10.3/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb:10.11/mariadb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mariadb:11.8/mariadb | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS3
Связанные уязвимости
(In MariaDB server version through 11.8.5, when server audit plugin is ...)
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
In MariaDB server version through 11.8.5, when server audit plugin is ...
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
4.3 Medium
CVSS3