First published: Tue Apr 16 2024(Updated: )
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 8.3.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL Installer | >=8.0.0<=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21090 is considered a high severity vulnerability due to its potential for easy exploitation by unauthenticated attackers.
To fix CVE-2024-21090, upgrade MySQL Connectors to version 8.3.1 or later.
CVE-2024-21090 affects MySQL Connectors versions 8.3.0 and earlier.
CVE-2024-21090 can be exploited by an unauthenticated attacker via multiple network protocols.
Yes, CVE-2024-21090 specifically impacts the MySQL Connectors product of Oracle MySQL.