cbcvebase.
CVE-2015-1027
published 2017-09-29

CVE-2015-1027: The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The…

PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.20%
64.6th percentile
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianpercona-toolkit< percona-toolkit 2.2.13-1 (bookworm)percona-toolkit 2.2.13-1 (bookworm)
perconatoolkit<= 2.2.12
perconaxtrabackup<= 2.2.8

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.