CVE-2020-2660: Medium severity Oracle MySQL vulnerability
Last updated 18 August 2025
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpujan2020.html
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 5.7.29 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.0.19 - Upgrade
Upgrade
Oracle MySQL (Server: Optimizer)to a version that resolves this vulnerability.Fixed in 5.7.29 - Upgrade
Upgrade
Oracle MySQL (Server: Optimizer)to a version that resolves this vulnerability.Fixed in 8.0.19 - Operational
After upgrading MySQL Server to a version not listed as affected, validate the server stability to ensure the hang or frequently repeatable crash (complete DOS) condition is resolved.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2660?
CVE-2020-2660 is classified as an easily exploitable vulnerability with a high severity rating regarding MySQL Server.
How do I fix CVE-2020-2660?
To fix CVE-2020-2660, upgrade MySQL Server to versions 5.7.29 or later, and 8.0.19 or later.
Which MySQL Server versions are affected by CVE-2020-2660?
CVE-2020-2660 affects MySQL Server versions 5.7.28 and prior, and 8.0.18 and prior.
Is CVE-2020-2660 specific to certain operating systems?
CVE-2020-2660 impacts MySQL Server regardless of operating system, but it is known to affect distributions like Ubuntu and Red Hat.
What types of attacks are possible with CVE-2020-2660?
CVE-2020-2660 allows an attacker with high privileges and network access to exploit the vulnerability in MySQL Server.