CVE-2024-21237: Low severity mysql vulnerability
Last updated 12 November 2024
Other sources
Oracle MySQL Server is vulnerable to a denial of service related to the Server: Group Replication GCS component. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
— Debian
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21237?
CVE-2024-21237 is considered difficult to exploit, but it involves high privileged actions that can affect MySQL Server components.
How do I fix CVE-2024-21237?
To mitigate CVE-2024-21237, upgrade MySQL Server to version 8.0.40-1 or higher.
Which versions of MySQL are affected by CVE-2024-21237?
CVE-2024-21237 affects MySQL versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior.
Who is impacted by CVE-2024-21237?
Organizations using affected versions of MySQL Server, especially with high privileged attackers, are impacted by CVE-2024-21237.
What is the component affected in CVE-2024-21237?
The vulnerability CVE-2024-21237 specifically affects the Group Replication GCS component of the MySQL Server.