CVE-2023-29194: vitess allows users to create keyspaces that can deny access to already existing keyspaces

Published Apr 11, 2023
·
Updated

Impact Users can either intentionally or inadvertently create a keyspace containing / characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using vtctldclient GetKeyspaces will also return an error. Note that all other keyspaces can still be administered using the CLI (vtctldclient).

Patches v16.0.1 (corresponding to 0.16.1 on pkg.go.dev)

Workarounds Delete the offending keyspace using a CLI client (vtctldclient) vtctldclient --server ... DeleteKeyspace a/b

Found during a security audit sponsored by the CNCF and facilitated by OSTIF.

Other sources

Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing / characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using vtctldclient GetKeyspaces will also return an error. Note that all other keyspaces can still be administered using the CLI (vtctldclient). This issue is fixed in version 16.0.1. As a workaround, delete the offending keyspace using a CLI client (vtctldclient).

Affected Software

2 affected componentsFixes available
go/vitess.io/vitess<0.16.1
0.16.1
linuxfoundation Vitess<16.0.1

Event History

Apr 11, 2023
Advisory Published
via GitHub·09:12 PM
Apr 14, 2023
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2023-29194?

CVE-2023-29194 has been reported as a vulnerability that can potentially disrupt user access to keyspaces in Vitess.

2

How do I fix CVE-2023-29194?

To address CVE-2023-29194, upgrade Vitess to version 0.16.1 or later.

3

What are the affected versions for CVE-2023-29194?

CVE-2023-29194 affects Vitess versions prior to 0.16.1.

4

Can CVE-2023-29194 impact database operations?

Yes, CVE-2023-29194 can prevent users from being able to list and access keyspaces, disrupting normal database operations.

5

What software is impacted by CVE-2023-29194?

CVE-2023-29194 affects Vitess software, specifically versions prior to 0.16.1 released by the Linux Foundation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203