Severity
7.5HIGH
EPSS
0.9%
top 24.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages3 packages

NVDoracle/mysql9.0.0

🔴Vulnerability Details

4
OSV
CVE-2024-21272: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python)2024-10-15
GHSA
MySQL Connector/Python connector takeover vulnerability2024-10-15
OSV
MySQL Connector/Python connector takeover vulnerability2024-10-15
CVEList
CVE-2024-21272: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python)2024-10-15

📋Vendor Advisories

2
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/Python — CVE-2024-212722024-10-15
Debian
CVE-2024-21272: mysql-connector-python - Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connec...2024
CVE-2024-21272 (HIGH CVSS 7.5) | Vulnerability in the MySQL Connecto | cvebase.io