CVE-2022-27381: SQL Injection
Published Apr 12, 2022
·Updated
An issue in the component Field::setdefault of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Affected Software
14 affected componentsFixes available
redhat/mariadb<10.7.4
10.7.4
redhat/mariadb<10.6.8
10.6.8
redhat/mariadb<10.5.16
10.5.16
redhat/mariadb<10.4.25
10.4.25
redhat/mariadb<10.3.35
10.3.35
redhat/mariadb<10.2.44
10.2.44
MariaDB MariaDB>=10.2.0<10.2.44
MariaDB MariaDB>=10.3.0<10.3.35
MariaDB MariaDB>=10.4.0<10.4.25
MariaDB MariaDB>=10.5.0<10.5.16
MariaDB MariaDB>=10.6.0<10.6.8
MariaDB MariaDB>=10.7.0<10.7.4
Debian Debian Linux=10.0
debian/mariadb-10.5
1:10.5.23-0+deb11u11:10.5.28-0+deb11u1
Event History
Apr 12, 2022
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
Description
Apr 16, 2024
Data Sourced
via Launchpad·02:06 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·02:30 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27381.
2
What is the severity of CVE-2022-27381?
The severity of CVE-2022-27381 is high.
3
What is the affected software for CVE-2022-27381?
The affected software for CVE-2022-27381 is MariaDB Server versions 10.6 and below.
4
How can attackers exploit CVE-2022-27381?
Attackers can exploit CVE-2022-27381 by using specially crafted SQL statements to cause a Denial of Service (DoS).
5
Are there any references related to CVE-2022-27381?
Yes, you can find references related to CVE-2022-27381 at the following links: [link1](https://jira.mariadb.org/browse/MDEV-26061), [link2](https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html), [link3](https://security.netapp.com/advisory/ntap-20220519-0006/).