CVE-2017-15365
Summary
| CVE | CVE-2017-15365 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-25 16:29:00 UTC |
| Updated | 2023-11-07 02:39:00 UTC |
| Description | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 26 | All | All | All |
| Operating System | Fedoraproject | Fedora | 26 | All | All | All |
| Application | Mariadb | Mariadb | All | All | All | All |
| Application | Mariadb | Mariadb | All | All | All | All |
| Application | Percona | Xtradb Cluster | All | All | All | All |
| Application | Percona | Xtradb Cluster | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Percona XtraDB Cluster 5.6.37-26.21-3 is Now Available - Percona Database Performance Blog | CONFIRM | www.percona.com | Release Notes, Vendor Advisory |
| MariaDB 10.2.10 Release Notes - MariaDB Knowledge Base | CONFIRM | mariadb.com | Release Notes, Vendor Advisory |
| [SECURITY] Fedora 26 Update: mariadb-10.1.30-1.fc26 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Debian -- Security Information -- DSA-4341-1 mariadb-10.1 | DEBIAN | www.debian.org | |
| MW-416 DDL replication moved after acl checking · MariaDB/server@0b5a525 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| [SECURITY] Fedora 26 Update: mariadb-10.1.30-1.fc26 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| 1524234 – (CVE-2017-15365) CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Percona XtraDB Cluster 5.7.19-29.22-3 | CONFIRM | www.percona.com | Release Notes, Vendor Advisory |
| MariaDB 10.1.30 Release Notes - MariaDB Knowledge Base | CONFIRM | mariadb.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.