← Back

CVE-2020-15180

nvd nist
Published: May 27, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

Affected (13)

Show all products
1 product
Mariadb
1 product
Debian Linux
1 product
Xtradb Cluster
1 product
Galera Cluster For Mysql
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mariadb
From 10.1.0 to 10.1.47
From 10.2.0 to 10.2.34
From 10.3.0 to 10.3.25
From 10.4.0 to 10.4.15
From 10.5.0 to 10.5.6
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Percona
Before 5.6.49-28.42.2
From 5.7 to 5.7.31-31.45.2
From 8.0 to 8.0.20-11.2
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Galeracluster
From 5.6 to 5.6.49
From 5.7 to 5.7.31
From 8.0 to 8.0.21

References (10)

Source: security-advisories@github.com
Issue TrackingThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.