CVE-2022-21454: Medium severity mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpuapr2022.html#AppendixMSQL
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21454?
CVE-2022-21454 is a vulnerability in the MySQL Server product of Oracle MySQL, specifically in the Server: Group Replication Plugin.
Which versions of Oracle MySQL are affected by CVE-2022-21454?
Versions 5.7.37 and prior, as well as 8.0.28 and prior, are affected by CVE-2022-21454.
How can CVE-2022-21454 be exploited?
CVE-2022-21454 can be exploited by a low privileged attacker with network access via multiple protocols.
What is the severity of CVE-2022-21454?
The severity of CVE-2022-21454 is medium with a CVSS score of 6.5.
Are there any remedies available for CVE-2022-21454?
Yes, Oracle has released patches for Oracle MySQL 5.7.38 and 8.0.29 to address the vulnerability.