CVE-2022-21315
published 2022-01-19CVE-2022-21315: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and…
PriorityP426medium6.3CVSS 3.1
AVAACHPRHUIRSUCHIHAH
EPSS
2.52%
83.2th percentile
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | cbl2_mysql_8.0.28-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_mysql_8.0.28-1_on_cbl_mariner_1.0 | — | — |
| oracle | mysql | 7.4.0 – 7.4.34 | — |
| oracle | mysql | 7.5.0 – 7.5.24 | — |
| oracle | mysql | 7.6.0 – 7.6.20 | — |
| oracle | mysql | 8.0.0 – 8.0.27 | — |
| oracle_corporation | mysql_cluster | — | — |
| oracle_corporation | mysql_cluster | — | — |
| oracle_corporation | mysql_cluster | — | — |
| oracle_corporation | mysql_cluster | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:A/AC:H/Au:S/C:P/I:P/A:P
cisa7.8HIGH
vendor_msrc6.3MEDIUM
vendor_oracle6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
System Information Library for Node.JS Command Injection
cisa·2022-01-18·CVSS 7.8
CVE-2021-21315 [HIGH] CWE-78 System Information Library for Node.JS Command Injection
Vulnerability: System Information Library for Node.JS Command Injection
Affected: Npm package System Information Library for Node.JS
In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21315
Remediation Due Date: 2022-02-01
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: General — CVE-2022-21315
vendor_oracle·2022-01-15·CVSS 6.3
CVE-2022-21315 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Cluster: General — CVE-2022-21315
Oracle Oracle MySQL Risk Matrix: Cluster: General vulnerability
CVE: CVE-2022-21315
CVSS: 6.3
Protocol: Multiple
Remote exploit: No
Affected versions: Adjacent
Network
Advisory: cpujan2022 (JAN 2022)
Microsoft
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior 7.5.24 and prior 7.6.20 and prior and 8.0.27 and pri
vendor_msrc·2022-01-11·CVSS 6.3
CVE-2022-21315 [MEDIUM] Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior 7.5.24 and prior 7.6.20 and prior and 8.0.27 and pri
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior 7.5.24 and prior 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library
GHSA
GHSA-vh4w-rxcq-jxpw: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)
ghsa_unreviewed·2022-01-20
CVE-2022-21315 [MEDIUM] GHSA-vh4w-rxcq-jxpw: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Suricata
ET EXPLOIT NodeJS System Information Library Command Injection Attempt (CVE-2021-21315)
suricata·2022-01-25·CVSS 7.1
CVE-2021-21315 [HIGH] ET EXPLOIT NodeJS System Information Library Command Injection Attempt (CVE-2021-21315)
ET EXPLOIT NodeJS System Information Library Command Injection Attempt (CVE-2021-21315)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT NodeJS System Information Library Command Injection Attempt (CVE-2021-21315)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/getServices?name"; fast_pattern; pcre:"/^(?:\x28|\x29|\x3c|\x3e|\x26|\x2a|\xe2|\x80|\x98|\x7c|\x3f|\x3b|\x5b|\x5d|\x5e|\x7e|\x21|\x2e|\xe2|\x80|\x9d|\x25|\x40|\x2f|\x5c|\x3a|\x2b|\x2c|\x60)/R"; content:"|3d|"; within:10; reference:cve,2021-21315; classtype:attempted-admin; sid:2034973; rev:3; metadata:attack_target Server, created_at 2022_01_25, cve CVE_2021_21315, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_K
No public exploits indexed.
No writeups or analysis indexed.
https://security.netapp.com/advisory/ntap-20220121-0008/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-22-100/https://security.netapp.com/advisory/ntap-20220121-0008/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-22-100/
2022-01-19
Published