CVE-2025-21534
published 2025-01-21CVE-2025-21534: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior…
PriorityP420medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.95%
57.7th percentile
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-8.0 | < mysql-8.0 8.0.40-1 (sid) | mysql-8.0 8.0.40-1 (sid) |
| oracle | mysql_server | 8.0.0 – 8.0.39 | — |
| oracle | mysql_server | 8.4.0 – 8.4.2 | — |
| oracle | mysql_server | 9.0.0 – 9.0.1 | — |
| oracle_corporation | mysql_server | * – 8.0.39 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
ghsa9.8CRITICAL
osv4.9MEDIUM
vendor_redhat9.8CRITICAL
vendor_debian4.9MEDIUM
vendor_oracle4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization
vendor_redhat·2025-02-15·CVSS 9.8
CVE-2025-1302 [CRITICAL] CWE-94 jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization
jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
**Note:**
This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).
A flaw was found in jsonpath-plus. This vulnerability allows remote code execution (RCE) via improper input sanitization, exploiting the unsafe default usage of eval='safe' mode.
Statement: Red Hat's initial impact rating of critical has been downgraded to low. While the vulnerable code is technically still present within Red Hat pro
Red Hat
mysql: MySQL Server: Denial of Service vulnerability via network access
vendor_redhat·2025-01-21·CVSS 4.9
CVE-2025-21534 [MEDIUM] mysql: MySQL Server: Denial of Service vulnerability via network access
mysql: MySQL Server: Denial of Service vulnerability via network access
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
A flaw was found in MySQL Server. This vulnerability allows a high privileged attacker to cause a complete denial of service (DoS)
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Performance Schema — CVE-2025-21534
vendor_oracle·2025-01-15·CVSS 4.9
CVE-2025-21534 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Performance Schema — CVE-2025-21534
Oracle Oracle MySQL Risk Matrix: Server: Performance Schema vulnerability
CVE: CVE-2025-21534
CVSS: 4.9
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Debian
CVE-2025-21534: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pe...
vendor_debian·2025·CVSS 4.9
CVE-2025-21534 [MEDIUM] CVE-2025-21534: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pe...
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Scope: local
sid: resolved (fixed in 8.0.40-1)
GHSA
JSONPath Plus allows Remote Code Execution
ghsa·2025-02-15·CVSS 9.8
CVE-2025-1302 [CRITICAL] CWE-94 JSONPath Plus allows Remote Code Execution
JSONPath Plus allows Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
**Note:**
This is caused by an incomplete fix for CVE-2024-21534.
OSV
CVE-2025-21534: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema)
osv·2025-01-21·CVSS 4.9
CVE-2025-21534 [MEDIUM] CVE-2025-21534: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA
GHSA-gg68-xh96-g8xv: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema)
ghsa_unreviewed·2025-01-21
CVE-2025-21534 [MEDIUM] CWE-770 GHSA-gg68-xh96-g8xv: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
No detection rules found.
Nuclei
JSONPath Plus < 10.3.0 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2025-1302 [CRITICAL] JSONPath Plus < 10.3.0 - Remote Code Execution
JSONPath Plus < 10.3.0 - Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534]
Template:
id: CVE-2025-1302
info:
name: JSONPath Plus < 10.3.0 - Remote Code Execution
author: Jaenact
severity: critical
description: |
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for
No writeups or analysis indexed.
2025-01-21
Published