Logo
vulnerabilityCVE-2024-21096
Name
CVE-2024-21096
Source
NVD ( link)Debian ( link)
Description
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mariadb
Patched

Vulnerability Ratings#


4.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.11.17
Not Affected
buildroot
master
10.11.17
Not Affected
openwrt
master
3.4.8-r3
Not Affected
openwrt
master
11.8.3-r1
Not Affected
openwrt
openwrt-25.12
3.4.8-r3
Not Affected
openwrt
openwrt-25.12
11.8.3-r1
Not Affected
yocto
master
11.4.12
Not Affected
yocto
scarthgap
10.11.16
Not Affected

Resolved with patches#


mariadb (yocto:kirkstone)

#
Title
Author
Resolve
1
MDEV-33727 update test results
Sergei Golubchik <serg@mariadb.org>
CVE-2024-21096
2
MDEV-34203 Sandbox mode \- is not compatible with
Oleksandr Byelkin <sanja@mariadb.com>
CVE-2024-21096
3
MDEV-33727 mariadb-dump trusts the server and does not
Sergei Golubchik <serg@mariadb.org>
CVE-2024-21096
4
also protect the /*!999999 sandbox comment
Sergei Golubchik <serg@mariadb.org>
CVE-2024-21096
5
MDEV-34318 mariadb-dump SQL syntax error with
Sergei Golubchik <serg@mariadb.org>
CVE-2024-21096