CVE-2017-15365
published 2018-01-25CVE-2017-15365: sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3…
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.29%
87.1th percentile
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mariadb | mariadb | < 10.1.30 | 10.1.30 |
| mariadb | mariadb | >= 0 < 10.1.32-r0 | 10.1.32-r0 |
| mariadb | mariadb | >= 0 < 10.1.32-r0 | 10.1.32-r0 |
| mariadb | mariadb | >= 0 < 10.1.32-r0 | 10.1.32-r0 |
| mariadb | mariadb | >= 0 < 10.1.32-r0 | 10.1.32-r0 |
| mariadb | mariadb | >= 10.2.0 < 10.2.10 | 10.2.10 |
| percona | xtradb_cluster | < 5.6.37-26.21-3 | 5.6.37-26.21-3 |
| percona | xtradb_cluster | >= 5.7.0 < 5.7.19-29.22-3 | 5.7.19-29.22-3 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5qvf-c9w3-cfj9: sql/event_data_objects
ghsa_unreviewed·2022-05-13
CVE-2017-15365 [HIGH] GHSA-5qvf-c9w3-cfj9: sql/event_data_objects
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
OSV
CVE-2017-15365: sql/event_data_objects
osv·2018-01-25·CVSS 8.8
CVE-2017-15365 [HIGH] CVE-2017-15365: sql/event_data_objects
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
Red Hat
mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
vendor_redhat·2017-10-06·CVSS 8.8
CVE-2017-15365 [HIGH] CWE-284 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
It was discovered that MariaDB could replicate certain data definition language (DDL) commands to other cluster nodes despite an access control check failure. A user with an SQL access to the server could possibly use this flaw to perform database modification on certain cluster nodes without having privileges to perform such chan
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [openstack-rdo]
bugzilla·2017-12-12·CVSS 8.8
CVE-2017-15365 [HIGH] CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [openstack-rdo]
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
I would
Bugzilla
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
bugzilla·2017-12-11·CVSS 8.8
CVE-2017-15365 [HIGH] CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks
MariaDB have noted in their release notes that reserved CVE-2017-15365 has been fixed in version 10.2.10[1], however they have not described how or what the vulnerability was. This CVE is also mentioned to affect Percona[2] with the fix is described as:
"Added access checks for DDL commands to make sure they do not get replicated if they failed without proper permissions"
A comparison with the MariaDB 10.2.10 changelog[3] and Percona description finds this commit[4], which seems a likely candidate for both describing and fixing the vulnerability.
The vulnerable code block in sql/event_data_objects.cc is also present in version 10.1, suggesting that it is also affected.
[0] http://cve.mitre.org/cgi
Bugzilla
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [fedora-all]
bugzilla·2017-12-11·CVSS 8.8
CVE-2017-15365 [HIGH] CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [fedora-all]
CVE-2017-15365 mariadb: Replication in sql/event_data_objects.cc occurs before ACL checks [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
https://access.redhat.com/errata/RHSA-2019:1258https://bugzilla.redhat.com/show_bug.cgi?id=1524234https://github.com/MariaDB/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ELCZV46WIYSJ6VMC65GMNN3A3QDRUJGK/https://mariadb.com/kb/en/library/mariadb-10130-release-notes/https://mariadb.com/kb/en/library/mariadb-10210-release-notes/https://www.debian.org/security/2018/dsa-4341https://www.percona.com/blog/2017/10/30/percona-xtradb-cluster-5-6-37-26-21-3-is-now-available/https://www.percona.com/doc/percona-xtradb-cluster/LATEST/release-notes/Percona-XtraDB-Cluster-5.7.19-29.22-3.htmlhttps://access.redhat.com/errata/RHSA-2019:1258https://bugzilla.redhat.com/show_bug.cgi?id=1524234https://github.com/MariaDB/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ELCZV46WIYSJ6VMC65GMNN3A3QDRUJGK/https://mariadb.com/kb/en/library/mariadb-10130-release-notes/https://mariadb.com/kb/en/library/mariadb-10210-release-notes/https://www.debian.org/security/2018/dsa-4341https://www.percona.com/blog/2017/10/30/percona-xtradb-cluster-5-6-37-26-21-3-is-now-available/https://www.percona.com/doc/percona-xtradb-cluster/LATEST/release-notes/Percona-XtraDB-Cluster-5.7.19-29.22-3.html
2018-01-25
Published