CVE-2022-25834: Command Injection
Published Jun 7, 2023
·Updated
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.
Affected Software
6 affected componentsFixes available
Percona XtraBackup<=2.2.24
Percona XtraBackup>=3.0<=8.0.27-19
debian/percona-xtrabackup
ubuntu/percona-xtrabackup<2.4.9-0ubuntu2+
2.4.9-0ubuntu2+
ubuntu/percona-xtrabackup<2.4.28, <8.0.32-26
2.4.288.0.32-26
ubuntu/percona-xtrabackup<2.3.7-0ubuntu0.16.04.2+
2.3.7-0ubuntu0.16.04.2+
Event History
Jun 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 22, 2024
Data Sourced
via Launchpad·01:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-25834.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19 a crafted filename on the local...'
3
What is the description of the vulnerability?
The vulnerability in Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19 allows a crafted filename on the local file system to trigger unexpected command shell execution of arbitrary commands.
4
Which software versions are affected by this vulnerability?
The vulnerability affects Percona XtraBackup versions 2.2.24 and 3.x through 8.0.27-19.
5
What is the severity of the vulnerability?
The vulnerability has a severity rating of 7.8 (high).