CVE-2020-15180: Command Injection
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in wsrepsstmethod allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.
Other sources
A malicious party with access to the WSREP service port (4567/TCP) as well as prerequisite knowledge of the configuration of the Galera cluster name is required in order to exploit this vulnerability, which leads to remote code execution via the WSREP protocol.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15180?
CVE-2020-15180 is a vulnerability found in the mysql-wsrep component of MariaDB that allows for command injection.
What is the impact of CVE-2020-15180?
CVE-2020-15180 threatens the system's confidentiality, integrity, and availability.
Which software versions are affected by CVE-2020-15180?
MariaDB versions 10.3.34 to 10.3.39, 10.5.21, and 10.1.47 to 10.1.47 are affected.
How can I fix CVE-2020-15180?
Update MariaDB to version 10.3.40, 10.5.22, or higher.
Where can I find more information about CVE-2020-15180?
You can find more information about CVE-2020-15180 at the following references: [Reference 1](https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-cluster/), [Reference 2](https://www.debian.org/security/2020/dsa-4776), [Reference 3](https://security.gentoo.org/glsa/202011-14)