Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-27928Code Injection in Mariadb

Severity
7.2HIGHNVD
EPSS
48.9%
top 2.23%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 19
Latest updateMay 24

Description

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

NVDpercona/percona_server2021-03-03
NVDmariadb/mariadb10.210.2.37+3
NVDgaleracluster/wsrep2021-03-03

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-2q7x-w5q3-rjxc: A remote code execution issue was discovered in MariaDB 102022-05-24
CVEList
CVE-2021-27928: A remote code execution issue was discovered in MariaDB 102021-03-19
OSV
CVE-2021-27928: A remote code execution issue was discovered in MariaDB 102021-03-19

💥Exploits & PoCs

1
Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution2021-04-14

📋Vendor Advisories

3
Red Hat
mariadb: writable system variables allows a database user with SUPER privilege to execute arbitrary code as the system mysql user2021-03-19
Microsoft
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37 10.3 before 10.3.28 10.4 before 10.4.18 and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch throu2021-03-09
Debian
CVE-2021-27928: mariadb-10.5 - A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10....2021
CVE-2021-27928 — Code Injection in Mariadb | cvebase