CVE-2024-21134 is a vulnerability affecting Oracle MySQL Server versions 8.0.37 and prior, and 8.4.0 and prior, specifically within the Connection Handling component. This easily exploitable flaw allows a low-privileged attacker with network access to cause a partial denial of service (DoS) of the MySQL Server. With a CVSS 3.1 Base Score of 4.3 (Medium), the attack requires no user interaction and has low attack complexity, impacting only availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.37CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
8.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:8.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-21134
Dec 10, 2024CVE-2024-21134
Nov 12, 2024CVE-2024-21134
Oct 8, 2024mysql: Connection Handling unspecified vulnerability (CPU Jul 2024)
Jul 16, 2024Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Jul 9, 2024