CVE-2020-14828: High severity mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpuoct2020.html#AppendixMSQL
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14828?
CVE-2020-14828 is classified as a high severity vulnerability affecting MySQL Server versions 8.0.21 and prior.
How do I fix CVE-2020-14828?
To fix CVE-2020-14828, upgrade your MySQL Server to version 8.0.22 or later.
What impact does CVE-2020-14828 have on MySQL Server?
CVE-2020-14828 allows a high privileged attacker with network access to compromise MySQL Server.
Which MySQL versions are affected by CVE-2020-14828?
CVE-2020-14828 affects MySQL Server versions 8.0.21 and earlier.
Who is at risk from CVE-2020-14828?
High privileged attackers with network access via multiple protocols are at risk of exploiting CVE-2020-14828.