CVE-2024-21096: Medium severity Oracle MySQL vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).
— Microsoft
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).
— NVD
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixMSQL
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mariadbto a version that resolves this vulnerability.Fixed in 1:11.4.3-1 - Upgrade
Upgrade
debian/mariadb-10.5to a version that resolves this vulnerability.Fixed in 1:10.5.26-0+deb11u2 - Upgrade
Upgrade
debian/mysql-8.0to a version that resolves this vulnerability.Fixed in 8.0.40-1 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.0.37 - Upgrade
Upgrade
redhat/mysqlto a version that resolves this vulnerability.Fixed in 8.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.40-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.6.20-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.11.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21096?
CVE-2024-21096 is classified as a difficult to exploit vulnerability that may permit unauthenticated attackers to gain access.
Which versions of MySQL are affected by CVE-2024-21096?
CVE-2024-21096 affects Oracle MySQL versions 8.0.36 and earlier, and 8.3.0 and earlier.
How do I fix CVE-2024-21096?
To fix CVE-2024-21096, update MySQL to version 8.0.40-1 or later for Debian, and 8.0.37 or later for RedHat.
Can CVE-2024-21096 be exploited remotely?
CVE-2024-21096 requires an authenticated logon to exploit, which mitigates the risk of remote exploitation.
What software components include the CVE-2024-21096 vulnerability?
CVE-2024-21096 is found in the MySQL Server product, particularly in the mysqldump client component.