CVE-2017-1000017: SSRF
Published Jul 13, 2017
·Updated
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
Affected Software
6 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=4.0<4.0.10.19
4.0.10.19
composer/phpmyadmin/phpmyadmin>=4.4<4.4.15.10
4.4.15.10
composer/phpmyadmin/phpmyadmin>=4.6<4.6.6
4.6.6
phpMyAdmin phpMyAdmin>=4.0.0<4.0.10.19
phpMyAdmin phpMyAdmin>=4.4.0<=4.4.15.10
phpMyAdmin phpMyAdmin>=4.6.0<=4.6.6
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:15 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000017?
CVE-2017-1000017 is considered a medium severity vulnerability.
2
How do I fix CVE-2017-1000017?
To fix CVE-2017-1000017, upgrade phpMyAdmin to version 4.0.10.19, 4.4.15.10, or 4.6.6.
3
What versions of phpMyAdmin are affected by CVE-2017-1000017?
phpMyAdmin versions 4.0.x, 4.4.x, and 4.6.x prior to their respective patched versions are affected.
4
What type of vulnerability is CVE-2017-1000017?
CVE-2017-1000017 is a permissions vulnerability that allows unauthorized MySQL connections.
5
Who can exploit CVE-2017-1000017?
A user with appropriate permissions can exploit CVE-2017-1000017 to connect to arbitrary MySQL servers.