First published: Mon Apr 27 2020(Updated: )
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Percona XtraBackup | >=2.4.11<2.4.20 | |
Percona XtraBackup | >=8.0.4<8.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10997 is a vulnerability in Percona XtraBackup before 2.4.20 that unintentionally writes the command line to any resulting backup file output, including sensitive arguments passed at runtime.
CVE-2020-10997 affects Percona XtraBackup versions before 2.4.20 and versions between 8.0.4 and 8.0.11. It may result in the disclosure of command line arguments passed at runtime.
CVE-2020-10997 has a severity rating of 6.5 out of 10 (medium).
To fix CVE-2020-10997, upgrade to Percona XtraBackup version 2.4.20 or newer.
For more information about CVE-2020-10997, you can refer to the following references: [link1](https://jira.percona.com/browse/PXB-2142) and [link2](https://www.percona.com/blog/2020/04/16/cve-2020-10997-percona-xtrabackup-information-disclosure-of-command-line-arguments/)