First published: Wed Jan 17 2024(Updated: )
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/mysql-8.0 | <8.0.36-0ubuntu0.20.04.1 | 8.0.36-0ubuntu0.20.04.1 |
ubuntu/mysql-8.0 | <8.0.36-0ubuntu0.22.04.1 | 8.0.36-0ubuntu0.22.04.1 |
ubuntu/mysql-8.0 | <8.0.36 | 8.0.36 |
ubuntu/mysql-8.0 | <8.0.36-0ubuntu0.23.10.1 | 8.0.36-0ubuntu0.23.10.1 |
redhat/mysql | <8.0.36 | 8.0.36 |
redhat/mysql | <8.2.1 | 8.2.1 |
debian/mysql-8.0 | 8.0.36-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20966 is considered a high-severity vulnerability due to its potential for exploitation by a high-privileged attacker.
CVE-2024-20966 affects MySQL Server versions 8.0.35 and earlier, as well as 8.2.0 and earlier.
To remediate CVE-2024-20966, upgrade MySQL to version 8.0.36 or later for supported releases.
CVE-2024-20966 may allow attackers with network access to compromise MySQL Server through easily exploitable means.
For more information regarding CVE-2024-20966, refer to Oracle as the vendor of MySQL Server.