First published: Wed Jun 07 2023(Updated: )
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Percona XtraBackup | <=2.2.24 | |
Percona XtraBackup | >=3.0<=8.0.27-19 | |
debian/percona-xtrabackup | ||
ubuntu/percona-xtrabackup | <2.4.9-0ubuntu2+ | 2.4.9-0ubuntu2+ |
ubuntu/percona-xtrabackup | <2.4.28<8.0.32-26 | 2.4.28 8.0.32-26 |
ubuntu/percona-xtrabackup | <2.3.7-0ubuntu0.16.04.2+ | 2.3.7-0ubuntu0.16.04.2+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25834.
The title of the vulnerability is 'In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19 a crafted filename on the local...'
The vulnerability in Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19 allows a crafted filename on the local file system to trigger unexpected command shell execution of arbitrary commands.
The vulnerability affects Percona XtraBackup versions 2.2.24 and 3.x through 8.0.27-19.
The vulnerability has a severity rating of 7.8 (high).