CVE-2021-2471

Severity
5.9MEDIUM
EPSS
63.8%
top 1.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 20
Latest updateMay 24

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repea

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:HExploitability: 0.7 | Impact: 5.2

Affected Packages9 packages

NVDoracle/mysql_connectors8.0.08.0.26
CVEListV5oracle_corporation/mysql_connectors8.0.26 and prior
Mavenmysql:mysql-connector-java8.0.08.0.27
Ubuntumysql-8.0< 8.0.27-0ubuntu0.20.04.1+1

🔴Vulnerability Details

4
OSV
Incorrect Authorization in MySQL Connector Java2022-05-24
GHSA
Incorrect Authorization in MySQL Connector Java2022-05-24
CVEList
CVE-2021-2471: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)2021-10-20
OSV
CVE-2021-2471: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)2021-10-20

📋Vendor Advisories

4
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (MySQL Connectors) — CVE-2021-24712022-04-15
Red Hat
mysql-connector-java: unauthorized access to critical2021-10-20
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/J — CVE-2021-24712021-10-15
Microsoft
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privil2021-10-12

💬Community

1
Bugzilla
CVE-2020-8169 libcurl: partial password leak over DNS on HTTP redirect2020-06-17