CVE-2024-20983: Medium severity ORACLE MySQL vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpujan2024.html#AppendixMSQL
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-3 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.20.04.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.0.35 - Upgrade
Upgrade
oracle/mysql (MySQL Server)to a version that resolves this vulnerability.Fixed in 8.0.34 - Compensating control
Until patched, mitigate network exposure by restricting inbound access to the MySQL Server from untrusted networks (the vulnerability is network-accessible via multiple protocols).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20983?
CVE-2024-20983 is classified as a high severity vulnerability that allows remote exploitation.
How do I fix CVE-2024-20983?
To fix CVE-2024-20983, upgrade MySQL Server to version 8.0.36 or later.
Which versions are affected by CVE-2024-20983?
CVE-2024-20983 affects MySQL Server versions 8.0.34 and earlier.
Can CVE-2024-20983 be exploited remotely?
Yes, CVE-2024-20983 can be easily exploited by a high privileged attacker with network access.
What component of MySQL is involved in CVE-2024-20983?
CVE-2024-20983 involves the DML component of the MySQL Server product.