Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23654
HistoryApr 10, 2020 - 12:32 a.m.

Authorization Bypass

2020-04-1000:32:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27

EPSS

0

Percentile

14.3%

mysql is vulnerable to authorization bypass. The vulnerability exists as it was discovered that the Red Hat Security Advisory RHSA-2008:0505, for Red Hat Application Stack v2.1, provided an incomplete fix for the flaw where MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access privileges to tables created by other database users. Note: This attack does not work on existing tables. An attacker can only elevate their access to another user’s tables as the tables are created. As well, the names of these created tables need to be predicted correctly for this attack to succeed.

References