[MAVEN:GHSA-G76J-4CXX-23H9] Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Package Affected Version
pkg:maven/mysql/mysql-connector-java <= 8.0.27
Package Fixed Version
pkg:maven/mysql/mysql-connector-java = 8.0.28
ID
MAVEN:GHSA-G76J-4CXX-23H9
Severity
moderate
URL
https://github.com/advisories/GHSA-g76j-4cxx-23h9
Published
2022-01-20T00:00:48
(2 years ago)
Modified
2023-01-27T05:00:34
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/mysql/mysql-connector-java mysql mysql-connector-java <= 8.0.27
Fixed pkg:maven/mysql/mysql-connector-java mysql mysql-connector-java = 8.0.28
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...