CVE-2019-2692 – mysql:mysql-connector-java
Package
Manager: maven
Name: mysql:mysql-connector-java
Vulnerable Version: >=0 <8.0.16
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00336 pctl0.55779
Details
Privilege escalation in mysql-connector-jav Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Metadata
Created: 2020-07-01T17:12:20Z
Modified: 2021-09-22T18:47:45Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-jcq3-cprp-m333/GHSA-jcq3-cprp-m333.json
CWE IDs: ["CWE-843"]
Alternative ID: GHSA-jcq3-cprp-m333
Finding: F113
Auto approve: 1