CVE-2020-14791: Low severity mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixMSQL
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this MySQL Server vulnerability?
The vulnerability ID for this MySQL Server vulnerability is CVE-2020-14791.
What is the affected software for this MySQL Server vulnerability?
The affected software for this MySQL Server vulnerability includes Oracle MySQL 8.0.21 and prior versions.
How can a high privileged attacker exploit this vulnerability?
A high privileged attacker with network access can exploit this vulnerability to compromise the MySQL Server.
How severe is this MySQL Server vulnerability?
This MySQL Server vulnerability has a severity rating of low (2.2).
How do I fix this MySQL Server vulnerability?
To fix this MySQL Server vulnerability, upgrade to version 8.0.22 or later.