cbcvebase.
CVE-2024-21096
published 2024-04-16

CVE-2024-21096: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0…

PriorityP422medium4.9CVSS 3.1
AVLACHPRNUINSUCLILAL
EPSS
0.42%
34.8th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianmariadb< mariadb 1:10.11.11-0+deb12u1 (bookworm)mariadb 1:10.11.11-0+deb12u1 (bookworm)
debianmariadb-10.5< mariadb 1:10.11.11-0+deb12u1 (bookworm)mariadb 1:10.11.11-0+deb12u1 (bookworm)
debianmysql-8.0< mariadb 1:10.11.11-0+deb12u1 (bookworm)mariadb 1:10.11.11-0+deb12u1 (bookworm)
debianpostgresql-13< postgresql-13 13.22-0+deb11u1 (bullseye)postgresql-13 13.22-0+deb11u1 (bullseye)
debianpostgresql-15< postgresql-13 13.22-0+deb11u1 (bullseye)postgresql-13 13.22-0+deb11u1 (bullseye)
debianpostgresql-17< postgresql-13 13.22-0+deb11u1 (bullseye)postgresql-13 13.22-0+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
mariadbmariadb>= 0 < 1:10.11.11-0+deb12u11:10.11.11-0+deb12u1
mariadbmariadb>= 0 < 1:10.11.8-11:10.11.8-1
mariadbmariadb>= 0 < 1:10.11.8-11:10.11.8-1
msrcazl3_mariadb_10.11.10-1_on_azure_linux_3.0
msrcazl3_mariadb_10.11.6-3_on_azure_linux_3.0
msrcazl3_mysql_8.0.36-1_on_azure_linux_3.0
msrcazl3_mysql_8.0.40-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_mariadb_10.6.20-1_on_cbl_mariner_2.0
msrccbl2_mariadb_10.6.9-6_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.36-1_on_cbl_mariner_2.0
msrccbl2_mysql_8.0.40-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
oraclemysql8.0.0 – 8.0.36

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_msrc4.9MEDIUM
vendor_oracle4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.