CVE-2024-21247
published 2024-10-15CVE-2024-21247: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and…
PriorityP413low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.62%
45.8th percentile
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-8.0 | < mysql-8.0 8.0.40-1 (sid) | mysql-8.0 8.0.40-1 (sid) |
| msrc | azl3_mysql_8.0.36-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_mysql_8.0.40-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_mysql_8.0.36-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_mysql_8.0.40-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | 8.0.0 – 8.0.39 | — |
| oracle | mysql | 8.4.0 – 8.4.2 | — |
| oracle_corporation | mysql_client | * – 8.0.39 | — |
| oracle_corporation | mysql_cluster | * – 7.5.35 | — |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
osv3.8LOW
vendor_debian3.8LOW
vendor_msrc3.8LOW
vendor_oracle3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: mysqldump unspecified vulnerability (CPU Oct 2024)
vendor_redhat·2024-10-15·CVSS 3.8
CVE-2024-21247 [LOW] mysql: mysqldump unspecified vulnerability (CPU Oct 2024)
mysql: mysqldump unspecified vulnerability (CPU Oct 2024)
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Package: mysql8.4 (Red Hat Enterprise Linux 10) - Affected
Oracle
Oracle Oracle MySQL Risk Matrix: Client: mysqldump — CVE-2024-21247
vendor_oracle·2024-10-15·CVSS 3.8
CVE-2024-21247 [LOW] Oracle Oracle MySQL Risk Matrix: Client: mysqldump — CVE-2024-21247
Oracle Oracle MySQL Risk Matrix: Client: mysqldump vulnerability
CVE: CVE-2024-21247
CVSS: 3.8
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Microsoft
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior 8.4.2 and prior and 9.0.1 and prior. Easily exploi
vendor_msrc·2024-10-08·CVSS 3.8
CVE-2024-21247 [LOW] Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior 8.4.2 and prior and 9.0.1 and prior. Easily exploi
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this
Debian
CVE-2024-21247: mysql-8.0 - Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: my...
vendor_debian·2024·CVSS 3.8
CVE-2024-21247 [LOW] CVE-2024-21247: mysql-8.0 - Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: my...
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Scope: local
sid: resolved (fixed in 8.0.40-1)
OSV
CVE-2024-21247: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump)
osv·2024-10-15·CVSS 3.8
CVE-2024-21247 [LOW] CVE-2024-21247: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump)
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
GHSA
GHSA-vchj-ggm5-9rcm: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump)
ghsa_unreviewed·2024-10-15
CVE-2024-21247 [LOW] CWE-284 GHSA-vchj-ggm5-9rcm: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump)
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-15
Published