logo

CVE-2023-22102 com.mysql:mysql-connector-j

Package

Manager: maven
Name: com.mysql:mysql-connector-j
Vulnerable Version: >=0 <8.2.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

EPSS: 0.00901 pctl0.74785

Details

MySQL Connectors takeover vulnerability Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors.

Metadata

Created: 2023-10-18T00:31:42Z
Modified: 2024-12-05T15:46:43Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json
CWE IDs: []
Alternative ID: GHSA-m6vm-37g8-gqvh
Finding: F039
Auto approve: 1