Oracle Mysql Cluster vulnerabilities

48 known vulnerabilities affecting oracle/mysql_cluster.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM32LOW8

Vulnerabilities

Page 2 of 3
CVE-2021-44533MEDIUMCVSS 5.3fixed in 8.0.29v8.0.292022-02-24
CVE-2021-44533 [MEDIUM] CWE-295 CVE-2021-44533: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguis Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allo
nvd
CVE-2021-44532MEDIUMCVSS 5.3≤ 8.0.292022-02-24
CVE-2021-44532 [MEDIUM] CWE-296 CVE-2021-44532: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass o
nvd
CVE-2021-35584MEDIUMCVSS 4.3≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35584 [MEDIUM] CVE-2021-35584: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: ndbcluster/plugin DD Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: ndbcluster/plugin DDL). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2021-35592MEDIUMCVSS 6.3≥ 7.5.0, ≤ 7.5.23≥ 7.6.0, ≤ 7.6.19+1 more2021-10-20
CVE-2021-35592 [MEDIUM] CWE-129 CVE-2021-35592: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluste
nvd
CVE-2021-35621MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35621 [MEDIUM] CVE-2021-35621: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2021-35593MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35593 [MEDIUM] CWE-787 CVE-2021-35593: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35594MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35594 [MEDIUM] CWE-129 CVE-2021-35594: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35590MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35590 [MEDIUM] CWE-787 CVE-2021-35590: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35598MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.33≥ 7.5.0, ≤ 7.5.23+2 more2021-10-20
CVE-2021-35598 [MEDIUM] CWE-129 CVE-2021-35598: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware wher
nvd
CVE-2021-35618LOWCVSS 1.8≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35618 [LOW] CVE-2021-35618: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful
nvd
CVE-2021-35613LOWCVSS 3.7≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35613 [LOW] CVE-2021-35613: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2021-22931CRITICALCVSS 9.8≤ 8.0.262021-08-16
CVE-2021-22931 [CRITICAL] CWE-170 CVE-2021-22931: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
nvd
CVE-2021-22939MEDIUMCVSS 5.3≤ 8.0.262021-08-16
CVE-2021-22939 [MEDIUM] CWE-295 CVE-2021-22939: If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthori If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
nvd
CVE-2021-2411LOWCVSS 3.7≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2411 [LOW] CVE-2021-2411: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module). Supporte Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized abilit
nvd
CVE-2021-22883HIGHCVSS 7.5≤ 8.0.252021-03-03
CVE-2021-22883 [HIGH] CWE-400 CVE-2021-22883: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack wh Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also
nvd
CVE-2021-22884HIGHCVSS 7.5≤ 8.0.252021-03-03
CVE-2021-22884 [HIGH] CVE-2021-22884: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection
nvd
CVE-2020-8277HIGHCVSS 7.5≤ 8.0.232020-11-19
CVE-2020-8277 [HIGH] CWE-400 CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice co A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
nvd
CVE-2020-14853MEDIUMCVSS 4.6≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14853 [MEDIUM] CVE-2020-14853: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks require human interaction from a person other
nvd
CVE-2020-8174HIGHCVSS 8.1≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-07-24
CVE-2020-8174 [HIGH] CWE-119 CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
nvd
CVE-2020-8172HIGHCVSS 7.4≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-06-08
CVE-2020-8172 [HIGH] CWE-295 CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 1 TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
nvd