CVE-2025-30710
published 2025-04-15CVE-2025-30710: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41…
PriorityP420medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.60%
44.5th percentile
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql_cluster | 8.0.0 – 8.0.41 | — |
| oracle | mysql_cluster | 8.4.0 – 8.4.4 | — |
| oracle | mysql_cluster | 9.0.0 – 9.2.0 | — |
| oracle_corporation | mysql_cluster | 8.0.0 – 8.0.41 | — |
| oracle_corporation | mysql_cluster | 8.4.0 – 8.4.4 | — |
| oracle_corporation | mysql_cluster | 9.0.0 – 9.2.0 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_oracle4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: NDBCluster Plugin — CVE-2025-30710
vendor_oracle·2025-04-15·CVSS 4.9
CVE-2025-30710 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Cluster: NDBCluster Plugin — CVE-2025-30710
Oracle Oracle MySQL Risk Matrix: Cluster: NDBCluster Plugin vulnerability
CVE: CVE-2025-30710
CVSS: 4.9
Protocol: Multiple
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
GHSA
GHSA-m56x-56wx-f6f3: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin)
ghsa_unreviewed·2025-04-15
CVE-2025-30710 [MEDIUM] CWE-284 GHSA-m56x-56wx-f6f3: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin)
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-15
Published