Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-21540

Опубликовано: 21 янв. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.4

Описание

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

РелизСтатусПримечание
devel

not-affected

this mysql cve does not affect mariadb
esm-apps/noble

not-affected

this mysql cve does not affect mariadb
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

not-affected

this mysql cve does not affect mariadb
oracular

ignored

end of life, was needs-triage
plucky

not-affected

this mysql cve does not affect mariadb
questing

not-affected

this mysql cve does not affect mariadb
upstream

not-affected

this mysql cve does not affect mariadb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

not-affected

this mysql cve does not affect mariadb
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

not-affected

this mysql cve does not affect mariadb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

this mysql cve does not affect mariadb
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

not-affected

this mysql cve does not affect mariadb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

this mysql cve does not affect mariadb
focal

ignored

end of standard support, was ignored [no more upstream support]
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

not-affected

this mysql cve does not affect mariadb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

not-affected

this mysql cve does not affect mariadb
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

this mysql cve does not affect mariadb
noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

not-affected

this mysql cve does not affect mariadb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

ignored

see notes
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

ignored

see notes
esm-infra/focal

DNE

esm-infra/xenial

ignored

see notes
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

released

8.0.41-0ubuntu0.20.04.1
focal

released

8.0.41-0ubuntu0.20.04.1
jammy

released

8.0.41-0ubuntu0.22.04.1
noble

released

8.0.41-0ubuntu0.24.04.1
oracular

released

8.0.41-0ubuntu0.24.10.1
plucky

DNE

questing

DNE

upstream

released

8.0.41

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 30%
0.00107
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
11 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
nvd
11 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
debian
11 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: ...

CVSS3: 5.4
github
11 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
fstec
11 месяцев назад

Уязвимость компонента Server: Security: Privileges системы управления базами данных Oracle MySQL Server, позволяющая нарушителю получить доступ на чтение данных, модифицировать данные или получить привилегированный доступ

EPSS

Процентиль: 30%
0.00107
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2025-21540