CVE-2023-21977
Published on: Not Yet Published
Last Modified on: 04/27/2023 03:15:00 PM UTC
Certain versions of Mysql from Oracle contain the following vulnerability:
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
- CVE-2023-21977 has been assigned by
secaler[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 8.0.32 and prior
CVSS3 Score: 4.9 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - April 2023 | Vendor Advisory www.oracle.com text/html |
![]() |
April 2023 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 199323 Ubuntu Security Notification for MySQL Vulnerabilities (USN-6060-1)
- 20344 Oracle MySQL April 2023 Critical Patch Update (CPUAPR2023)
- 296101 Oracle Solaris 11.4 Support Repository Update (SRU) 59.138.2 Missing (CPUJUL2023)
- 691150 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (f504a8d2-e105-11ed-85f6-84a93843eb75)
- 906839 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (26178-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Oracle | Mysql | All | All | All | All |
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-21977 : Vulnerability in the MySQL Server product of Oracle MySQL component: Server: Optimizer . Support… twitter.com/i/web/status/1… | 2023-04-18 20:27:27 |