First published: Fri Mar 19 2021(Updated: )
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mariadb Mariadb | >=10.2<10.2.37 | |
Mariadb Mariadb | >=10.3<10.3.28 | |
Mariadb Mariadb | >=10.4<10.4.18 | |
Mariadb Mariadb | >=10.5<10.5.9 | |
Percona Percona Server | <=2021-03-03 | |
Galeracluster Wsrep | <=2021-03-03 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27928 is critical with a CVSS score of 7.2.
MariaDB versions before 10.2.37, 10.3.28, 10.4.18, and 10.5.9, Percona Server through 2021-03-03, and Galeracluster Wsrep through 2021-03-03 for MySQL are affected.
CVE-2021-27928 is a remote code execution issue in MariaDB, Percona Server, and Galeracluster Wsrep for MySQL. An untrusted search path leads to eval injection, allowing an attacker to execute arbitrary code.
Yes, you can find more information about CVE-2021-27928 at the following links: [http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html](http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html), [https://jira.mariadb.org/browse/MDEV-25179](https://jira.mariadb.org/browse/MDEV-25179), [https://lists.debian.org/debian-lts-announce/2021/03/msg00028.html](https://lists.debian.org/debian-lts-announce/2021/03/msg00028.html).
To fix CVE-2021-27928, update MariaDB to version 10.2.37, 10.3.28, 10.4.18, or 10.5.9, update Percona Server to a version after 2021-03-03, or update Galeracluster Wsrep to a version after 2021-03-03.