Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38668
HistoryDec 27, 2022 - 8:59 a.m.

Arbitrary Command Execution

2022-12-2708:59:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
shardingsphere-proxy
arbitrary code execution
client authentication
database sessions

EPSS

0.03

Percentile

91.0%

Shardingsphere-proxy is vulnerable to arbitrary code execution. The vulnerability exists because the mysql database backend fails to properly validate client authentication and does not clear out database sessions on time which allows an attacker to execute commands.

EPSS

0.03

Percentile

91.0%

Related for VERACODE:38668