First published: Thu Oct 17 2024(Updated: )
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MariaDB Server | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39593 is classified as a medium risk due to the potential for authenticated attackers to execute arbitrary commands.
To fix CVE-2023-39593, it is recommended to review and modify the permissions associated with the sys_exec function in MariaDB v10.5.
CVE-2023-39593 affects all users of MariaDB version 10.5 who have enabled the sys_exec function.
CVE-2023-39593 can facilitate attacks where authenticated users can execute commands with elevated privileges, potentially compromising system security.
The MariaDB Foundation disputes the severity of CVE-2023-39593, stating that no privilege boundary is crossed.