CVE-2020-2584: Medium severity Oracle MySQL vulnerability
Last updated 18 August 2025
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data.
External References:
https://www.oracle.com/security-alerts/cpujan2020.html
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 5.7.29 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.0.19 - Upgrade
Upgrade
oracle-mysql/Server (Options)to a version that resolves this vulnerability.Fixed in 5.7.28 - Upgrade
Upgrade
oracle-mysql/Server (Options)to a version that resolves this vulnerability.Fixed in 8.0.18
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2584?
CVE-2020-2584 is classified as a difficult-to-exploit vulnerability that allows high privileged attackers with network access to potentially exploit MySQL Server.
How do I fix CVE-2020-2584?
To mitigate CVE-2020-2584, update MySQL to version 5.7.29 or later, or 8.0.19 or later depending on your current version.
Which MySQL Server versions are affected by CVE-2020-2584?
CVE-2020-2584 affects MySQL Server versions 5.7.28 and prior, as well as 8.0.18 and prior.
Can CVE-2020-2584 be exploited remotely?
Yes, CVE-2020-2584 can be exploited remotely by attackers with high privileges and network access.
What components of MySQL are impacted by CVE-2020-2584?
The vulnerability affects the MySQL Server product specifically in the Server: Options component.