CVE-2021-2020
published 2021-01-20CVE-2021-2020: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.94%
85.6th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-8.0 | < mysql-8.0 8.0.21-1 (sid) | mysql-8.0 8.0.21-1 (sid) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| oracle | mysql | 8.0.0 – 8.0.20 | — |
| oracle_corporation | mysql_server | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_oracle9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fm4-277p-mcg2: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
ghsa_unreviewed·2022-05-24
CVE-2021-2020 [MEDIUM] GHSA-4fm4-277p-mcg2: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
OSV
CVE-2021-2020: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
osv·2021-01-20·CVSS 6.5
CVE-2021-2020 [MEDIUM] CVE-2021-2020: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Oracle
Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (Coherence) — CVE-2020-2555
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2020-2555 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (Coherence) — CVE-2020-2555
Oracle Oracle Commerce Risk Matrix: Dynamo Application Framework (Coherence) vulnerability
CVE: CVE-2020-2555
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
vendor_redhat·2021-01-19·CVSS 6.5
CVE-2021-2020 [MEDIUM] mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2021)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: mariadb:10.3/mariadb (Red Hat Enterprise Linux 8) - N
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Optimizer — CVE-2021-2020
vendor_oracle·2021-01-15·CVSS 6.5
CVE-2021-2020 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Optimizer — CVE-2021-2020
Oracle Oracle MySQL Risk Matrix: Server: Optimizer vulnerability
CVE: CVE-2021-2020
CVSS: 6.5
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle GraalVM Risk Matrix: Java — CVE-2020-14803
vendor_oracle·2021-01-15·CVSS 5.3
CVE-2020-14803 [MEDIUM] Oracle Oracle GraalVM Risk Matrix: Java — CVE-2020-14803
Oracle Oracle GraalVM Risk Matrix: Java vulnerability
CVE: CVE-2020-14803
CVSS: 5.3
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Chrome
Stable Channel Update for Desktop: CVE-2021-21106
vendor_chrome·2021-01-06·CVSS 9.6
CVE-2021-21106 [HIGH] Stable Channel Update for Desktop: CVE-2021-21106
Stable Channel Update for Desktop
CVE-2021-21106: Use after free in autofill. Reported by Weipeng Jiang (@Krace) from Codesafe Team of Legendsec at Qi'anxin Group on 2020-11-13 [$20000][ 1153595 ] High CVE-2021-21107: Use after free in drag and drop
Reported by Leecraso and Guang Gong of 360 Alpha Lab on 2020-11-30 [$20000][ 1155426 ] High CVE-2021-21108: Use after free in media
Severity: high
Debian
CVE-2021-2020: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...
vendor_debian·2021·CVSS 6.5
CVE-2021-2020 [MEDIUM] CVE-2021-2020: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Op...
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Scope: local
sid: resolved (fixed in 8.0.21-1)
Suricata
ET EXPLOIT EyesOfNetwork Generate API Key SQLi (CVE-2020-8656)
suricata·2021-11-01·CVSS 9.8
CVE-2020-8657 [CRITICAL] ET EXPLOIT EyesOfNetwork Generate API Key SQLi (CVE-2020-8656)
ET EXPLOIT EyesOfNetwork Generate API Key SQLi (CVE-2020-8656)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT EyesOfNetwork Generate API Key SQLi (CVE-2020-8656)"; flow:established,to_server; http.uri; content:"/eonapi/getApiKey"; fast_pattern; content:"username="; nocase; startswith; pcre:"/^[^&=]*(?:union|select)/Ri"; reference:url,www.exploit-db.com/exploits/48169; reference:cve,2020-8657; reference:cve,2020-8656; classtype:attempted-admin; sid:2034310; rev:1; metadata:attack_target Server, created_at 2021_11_01, cve CVE_2020_8656, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, updated_at 2021_11_01, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exp
Nuclei
Canon Devices - Authentication Bypass in Catwalk Server
nuclei·CVSS 7.5
CVE-2021-38154 [HIGH] Canon Devices - Authentication Bypass in Catwalk Server
Canon Devices - Authentication Bypass in Catwalk Server
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify an e-mail address setting, and thus cause the device to send sensitive information through e-mail to the attacker. For example, an incoming FAX may be sent through e-mail to the attacker. This occurs when a PIN is not required for General User Mode, as exploited in the wild in August 2021.
Template:
id: CVE-2021-38154
info:
name: Canon Devices - Authentication Bypass in Catwalk Server
author: daffainfo
severity: high
description: |
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is
Checkpoint
31st October – Threat Intelligence Report
blogs_checkpoint·2022-10-31
CVE-2022-3723 31st October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US-based communications company Twilio has disclosed a new data breach that occurred on June 2022 allegedly by the same threat actors behind the August hack. The hackers have used voice phishing to trick a Twilio employee into handling over their credentials, which the hackers then used to access customer information.
Cu
Checkpoint
10th October – Threat Intelligence Report
blogs_checkpoint·2022-10-10
CVE-2022-41352 10th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
CommonSpirit Health, the second-largest nonprofit hospital chain in the U.S with 140 hospitals and over 1,000 facilities in 21 states, suffered a cybersecurity incident that disrupted medical services across the country. Facilities in Iowa, Nebraska, Tennessee and Washington were among those affected. The nature of the at
Checkpoint
28th June – Threat Intelligence Report
blogs_checkpoint·2021-06-28
CVE-2021-21998 28th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Russian-based threat group Nobelium is using password spraying and brute force attacks to gain access to corporate networks. The group, which was behind the SolarWinds supply-chain attack, deployed an information-stealing Trojan on a Microsoft customer support agent’s computer to steal information. Over half of the targets were
Bugzilla
CVE-2020-13920 activemq: improper authentication allows MITM attack
bugzilla·2020-09-17·CVSS 5.9
CVE-2020-13920 [MEDIUM] CVE-2020-13920 activemq: improper authentication allows MITM attack
CVE-2020-13920 activemq: improper authentication allows MITM attack
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.
Reference:
http://activemq.apache.org/security-advisories.data/CVE-2020-13920-announcement.txt
Discussion:
This issue has been addressed in the following products:
Red Hat Fuse 7.9
Via RHSA-2021:3140 https://access.redhat.com/errata/RHSA-2021:3140
-
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CS5THZSGI7O2CZO44NWYE57AG2T7NK3K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T7EAHJPWOOF4D6PEFLXW5IQWRRSZ3HRC/https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20210219-0003/https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CS5THZSGI7O2CZO44NWYE57AG2T7NK3K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T7EAHJPWOOF4D6PEFLXW5IQWRRSZ3HRC/https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20210219-0003/https://www.oracle.com/security-alerts/cpujan2021.html
2021-01-20
Published