Логотип exploitDog
bind:CVE-2022-31011
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31011

Количество 2

Количество 2

nvd логотип

CVE-2022-31011

больше 3 лет назад

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4whx-7p29-mq22

больше 3 лет назад

TiDB authentication bypass vulnerability

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31011

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4whx-7p29-mq22

TiDB authentication bypass vulnerability

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу