First published: Tue Jul 20 2021(Updated: )
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL Cluster | >=8.0.0<=8.0.25 | |
NetApp OnCommand Insight |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2411 is classified as a difficult to exploit vulnerability that poses a risk to MySQL Cluster.
To mitigate CVE-2021-2411, upgrade to MySQL Cluster version 8.0.26 or later.
CVE-2021-2411 affects MySQL Cluster versions 8.0.25 and earlier.
Yes, CVE-2021-2411 allows unauthenticated attackers with network access to potentially exploit the vulnerability.
CVE-2021-2411 impacts the MySQL Cluster product of Oracle MySQL and also affects NetApp OnCommand Insight.