First published: Thu Oct 17 2024(Updated: )
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ariadne CMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26785 is classified as a remote code execution (RCE) vulnerability, which can lead to significant security risks.
To mitigate CVE-2023-26785, it is advised to upgrade to the latest version of MariaDB that addresses this vulnerability.
CVE-2023-26785 affects users of MariaDB v10.5 due to the specific vulnerability in UDF Code.
Yes, CVE-2023-26785 can be exploited remotely due to its nature as a remote code execution vulnerability.
Yes, the MariaDB Foundation disputes the vulnerability's impact, claiming no privilege boundary is crossed.