Galeracluster maintains a synchronous replication solution for MySQL that enables multi-master database clustering, with its vulnerability footprint concentrated in the Galera Cluster and WSREP components. The observed weakness classes center on code injection and command injection conditions, along with improper input validation, which reflect the parsing and execution demands of database replication and cluster coordination logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Galeracluster over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27928HIGH A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; an | Mar 19, 2021 | 7.2 | 56 | NO | YES |
CVE-2020-15180CRITICAL A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker t | May 27, 2021 | 9.0 | 31 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Galeracluster.
Media articles that mention a CVE ID that affects a product developed by Galeracluster — matched by CVE ID, not by vendor name.