CVE-2024-21013: Medium severity mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21013?
CVE-2024-21013 is classified as a difficult to exploit vulnerability that affects high privileged users with network access.
How do I fix CVE-2024-21013?
To remediate CVE-2024-21013, upgrade to MySQL Server version 8.0.40-1 or higher.
Which MySQL versions are affected by CVE-2024-21013?
CVE-2024-21013 affects MySQL Server versions 8.0.36 and prior and 8.3.0 and prior.
What components of MySQL does CVE-2024-21013 impact?
CVE-2024-21013 impacts the Optimizer component of the MySQL Server product.
Who can exploit CVE-2024-21013?
CVE-2024-21013 can potentially be exploited by a high privileged attacker with network access.