CVE-2023-22102 – com.mysql:mysql-connector-j
Package
Manager: maven
Name: com.mysql:mysql-connector-j
Vulnerable Version: >=0 <8.2.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS: 0.00901 pctl0.74785
Details
MySQL Connectors takeover vulnerability Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors.
Metadata
Created: 2023-10-18T00:31:42Z
Modified: 2024-12-05T15:46:43Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-m6vm-37g8-gqvh/GHSA-m6vm-37g8-gqvh.json
CWE IDs: []
Alternative ID: GHSA-m6vm-37g8-gqvh
Finding: F039
Auto approve: 1