icon

We found results for “

CVE-2020-15180

Good to know:

icon

Date: May 27, 2021

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

Language: C++

Severity Score

Severity Score

Weakness Type (CWE)

Command Injection

CWE-77

Input Validation

CWE-20

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

CWE-96

Top Fix

icon

Upgrade Version

Upgrade to version wsrep_5.6.49-25.31, wsrep_5.7.31-25.23

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): PARTIAL
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us