CVE-2024-20984: Medium severity ORACLE MySQL Server vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpujan2024.html#AppendixMSQL
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-3 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.20.04.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.36 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.0.36 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.2.1 - Upgrade
Upgrade
oracle/mysql/Server: Security : Firewallto a version that resolves this vulnerability.Fixed in 8.0.35 and prior - Upgrade
Upgrade
oracle/mysql/Server: Security : Firewallto a version that resolves this vulnerability.Fixed in 8.2.0 and prior - Compensating control
Because a successful attack can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, restrict network access to the MySQL Server using the Server : Security : Firewall (per the material’s referenced firewall guidance) to limit which network clients can reach MySQL via the multiple protocols.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20984?
CVE-2024-20984 is classified as a difficult to exploit vulnerability with a high privilege risk.
Which MySQL Server versions are affected by CVE-2024-20984?
CVE-2024-20984 affects MySQL Server versions 8.0.35 and earlier, as well as 8.2.0 and earlier.
How do I fix CVE-2024-20984?
To fix CVE-2024-20984, upgrade to MySQL Server version 8.0.36 or 8.2.1.
Who can exploit CVE-2024-20984?
CVE-2024-20984 can potentially be exploited by high-privileged attackers with network access.
What component of MySQL Server is affected by CVE-2024-20984?
CVE-2024-20984 affects the Security: Firewall component of the MySQL Server product.