CVE-2024-21185: Medium severity oracle mysql vulnerability
Last updated 31 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38, 8.4.1 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21185?
CVE-2024-21185 is considered an easily exploitable vulnerability that allows a high privileged attacker to compromise MySQL.
How do I fix CVE-2024-21185?
To mitigate CVE-2024-21185, upgrade MySQL Server to version 8.0.39-1 or later.
Which versions of MySQL Server are affected by CVE-2024-21185?
CVE-2024-21185 affects MySQL Server versions 8.0.38, 8.4.1, and 9.0.0.
What components of MySQL are impacted by CVE-2024-21185?
CVE-2024-21185 affects the InnoDB component of MySQL Server.
How can attackers exploit CVE-2024-21185?
Attackers can exploit CVE-2024-21185 remotely through multiple protocols if they have high privileges.