Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3494

Опубликовано: 03 мар. 2026
Источник: redhat
CVSS3: 4.3

Описание

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

A flaw was found in MariaDB. An authenticated database user can exploit this vulnerability by invoking SQL statements prefixed with double-hyphen (—) or hash (#) style comments. When the server audit plugin is enabled with specific event filtering, these statements are not logged. This oversight can lead to critical database operations bypassing audit logging, hindering security monitoring and compliance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mariadb10.11Fix deferred
Red Hat Enterprise Linux 10mariadb11.8Fix deferred
Red Hat Enterprise Linux 7mariadbFix deferred
Red Hat Enterprise Linux 8mariadb:10.11/mariadbFix deferred
Red Hat Enterprise Linux 8mariadb:10.3/mariadbFix deferred
Red Hat Enterprise Linux 8mariadb:10.5/mariadbFix deferred
Red Hat Enterprise Linux 8mariadb-devel:10.3/mariadbFix deferred
Red Hat Enterprise Linux 9mariadbFix deferred
Red Hat Enterprise Linux 9mariadb:10.11/mariadbFix deferred
Red Hat Enterprise Linux 9mariadb:11.8/mariadbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2444155MariaDB: MariaDB: Information disclosure due to unlogged SQL statements with comments

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
20 дней назад

(In MariaDB server version through 11.8.5, when server audit plugin is ...)

CVSS3: 4.3
nvd
5 месяцев назад

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

CVSS3: 4.3
msrc
5 месяцев назад

MariaDB Server Audit Plugin Comment Handling Bypass

CVSS3: 4.3
debian
5 месяцев назад

In MariaDB server version through 11.8.5, when server audit plugin is ...

CVSS3: 4.3
github
5 месяцев назад

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.

4.3 Medium

CVSS3