CVE-2023-22048: Low severity oracle mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data.
External References:
https://www.oracle.com/security-alerts/cpujul2023.html#AppendixMSQL
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22048?
The severity of CVE-2023-22048 is low (3.1).
Which versions of Oracle MySQL are affected by CVE-2023-22048?
The affected versions of Oracle MySQL are 8.0.33 and prior.
How can a low privileged attacker exploit CVE-2023-22048?
A low privileged attacker with network access via multiple protocols can compromise MySQL Server.
Is there a fix available for CVE-2023-22048?
Yes, the fix for CVE-2023-22048 is available in version 8.0.34 of MySQL Server.
Where can I find more information about CVE-2023-22048?
You can find more information about CVE-2023-22048 on the Oracle Security Alerts website and the NetApp security advisory.