CVE-2020-14878: High severity mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14878?
CVE-2020-14878 is considered a high-severity vulnerability due to its potential for exploitation by low-privileged attackers.
How do I fix CVE-2020-14878?
To fix CVE-2020-14878, upgrade your MySQL Server to version 8.0.22 or later.
Who is affected by CVE-2020-14878?
CVE-2020-14878 affects users of MySQL Server version 8.0.21 and prior.
What kind of attack can exploit CVE-2020-14878?
CVE-2020-14878 can be exploited by attackers with access to the physical communication segment of the MySQL Server.
What component of MySQL is vulnerable in CVE-2020-14878?
CVE-2020-14878 affects the LDAP authentication component of MySQL Server.