CVE-2024-20994: Medium severity oracle mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20994?
CVE-2024-20994 is classified as a difficult to exploit vulnerability that affects low privileged attackers with network access.
How do I fix CVE-2024-20994?
To remediate CVE-2024-20994, upgrade MySQL Server to version 8.0.40-1 or later for affected versions.
Which versions of MySQL Server are affected by CVE-2024-20994?
CVE-2024-20994 affects MySQL Server versions 8.0.36 and earlier as well as version 8.3.0 and earlier.
What component is impacted by CVE-2024-20994?
CVE-2024-20994 impacts the Information Schema component of the MySQL Server product from Oracle.
Is there a specific vendor that has acknowledged CVE-2024-20994?
Yes, Oracle has acknowledged CVE-2024-20994 and provided a fix in their security updates.