PT-2024-3454 · Oracle+5 · Mysql Server+4

CVE-2024-21050

·

Published

2024-02-20

·

Updated

2025-01-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MySQL Server versions 8.0.34 and prior
Description: The issue allows a high privileged attacker with network access via multiple protocols to compromise MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server. This can be achieved through exploitation of the vulnerability in the Server: DML component.
Recommendations: For versions 8.0.34 and prior, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11520
ALT-PU-2024-12462
ALT-PU-2024-7978
ALT-PU-2024-8426
BDU:2024-03740
CESA-2024_0894
CVE-2024-21050
INFSA-2024_1141
OESA-2024-2071
RHSA-2024:0894
RHSA-2024:1141
RHSA-2024:2619
RHSA-2024_0894
RHSA-2024_1141

Affected Products

Alt Linux
Centos
Mysql Server
Red Hat
Rocky Linux