Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-21874
HistoryJan 18, 2023 - 12:00 a.m.

CVE-2023-21874

2023-01-1800:00:00
ubuntu.com
ubuntu.com
17
vulnerability
oracle mysql server
high privileged attacker
multiple protocols
partial denial of service

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

17.3%

Vulnerability in the MySQL Server product of Oracle MySQL (component:
Server: Thread Pooling). Supported versions that are affected are 8.0.30
and prior. Easily exploitable vulnerability allows high privileged attacker
with network access via multiple protocols to compromise MySQL Server.
Successful attacks of this vulnerability can result in unauthorized ability
to cause a partial denial of service (partial DOS) of MySQL Server. CVSS
3.1 Base Score 2.7 (Availability impacts). CVSS Vector:
(CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

Notes

Author Note
leosilva since 5.5 is no longer upstream supported and so far we cannot patch it, marking it as ignored.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchmysql-8.0<ย 8.0.31-0ubuntu0.20.04.1UNKNOWN
ubuntu22.04noarchmysql-8.0<ย 8.0.31-0ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchmysql-8.0<ย 8.0.31-0ubuntu2UNKNOWN
ubuntu23.04noarchmysql-8.0<ย 8.0.31-0ubuntu2UNKNOWN
ubuntu23.10noarchmysql-8.0<ย 8.0.31-0ubuntu2UNKNOWN
ubuntu24.04noarchmysql-8.0<ย 8.0.31-0ubuntu2UNKNOWN
ubuntu16.04noarchpercona-server-5.6<ย anyUNKNOWN
ubuntu16.04noarchpercona-xtradb-cluster-5.6<ย anyUNKNOWN

CVSS3

2.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

17.3%