CVE-2023-29195

Summary

CVECVE-2023-29195
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2023-05-11 20:15:00 UTC
Updated2023-05-22 18:15:00 UTC
DescriptionVitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creating a shard using `vtctldclient` does not have the same problem because the CLI validates the input correctly. Version 16.0.2, corresponding to version 0.16.2 of the `go` module, contains a patch for this issue. Some workarounds are available. Always use `vtctldclient` to create shards, instead of using VTAdmin; disable creating shards from VTAdmin using RBAC; and/or delete the topology record for the offending shard using the client for your topology server.

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Linuxfoundation Vitess All All All All

References

ReferenceSourceLinkTags
Backport: [topo] Disallow the slash character in shard names #12843 (… · vitessio/vitess@9dcbd7d · GitHub MISC github.com
VTAdmin users that can create shards can deny access to other functions · Advisory · vitessio/vitess · GitHub MISC github.com
Release Vitess v16.0.2 · vitessio/vitess · GitHub MISC github.com
vitess command - vitess.io/vitess - Go Packages MISC pkg.go.dev
[topo] Disallow the slash character in shard names by ajm188 · Pull Request #12843 · vitessio/vitess · GitHub MISC github.com
Bug Report: CreateShard allows shard names with "/", which breaks other commands/components · Issue #12842 · vitessio/vitess · GitHub MISC github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 906952 Common Base Linux Mariner (CBL-Mariner) Security Update for vitess (26696-1)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report