Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.4.0, <= 8.4.10CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | ||
9.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:9.7.0:*:*:*:*:*:*:* | ||
9.7.1CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_server:9.7.1:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.47CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* | ||
>= 8.4.0, <= 8.4.10CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.