First published: Thu Jun 02 2022(Updated: )
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table. NOTE: this issue exists because of an incomplete fix for CVE-2020-10997.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Percona XtraBackup | =2.4.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26944 is a vulnerability in Percona XtraBackup 2.4.20 where the command line used to create a backup file is unintentionally written to the backup file, potentially exposing sensitive arguments.
CVE-2022-26944 affects Percona XtraBackup 2.4.20 as it inadvertently writes the command line used to create a backup file to the output, which may include sensitive arguments passed at runtime.
The severity of CVE-2022-26944 is medium, with a CVSS score of 6.5.
To fix CVE-2022-26944, upgrade to Percona XtraBackup 2.4.25 or later.
More information about CVE-2022-26944 can be found in the release notes for Percona XtraBackup 2.4.25 and in the associated JIRA ticket.