Percona Server vulnerabilities

7 known vulnerabilities affecting percona/percona_server.

Total CVEs
7
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4

Vulnerabilities

Page 1 of 1
CVE-2022-34968HIGHCVSS 7.5v8.0.28-192022-08-03
CVE-2022-34968 [HIGH] CWE-89 CVE-2022-34968: An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.
nvd
CVE-2021-27928HIGHCVSS 7.2PoC≤ 2021-03-032021-03-19
CVE-2021-27928 [HIGH] CWE-94 CVE-2021-27928: A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10 A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep
nvd
CVE-2020-26542CRITICALCVSS 9.8≤ 2020-10-022020-11-09
CVE-2020-26542 [CRITICAL] CWE-287 CVE-2020-26542: An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the servi
nvd
CVE-2019-12301CRITICALCVSS 9.8v5.6.44-85.0-12019-05-23
CVE-2019-12301 [CRITICAL] CVE-2019-12301: The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server w The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in 5.6.44-85.0-2.
nvd
CVE-2016-6664HIGHCVSS 7.0PoC≥ 5.5, < 5.5.51-38.2≥ 5.6, < 5.6.32-78.1+1 more2016-12-13
CVE-2016-6664 [HIGH] CWE-59 CVE-2016-6664: mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access
nvd
CVE-2016-6663HIGHCVSS 7.0PoC≥ 5.5, < 5.5.51-38.2≥ 5.6, < 5.6.32-78.1+1 more2016-12-13
CVE-2016-6663 [HIGH] CWE-362 CVE-2016-6663: Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x befo Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x
nvd
CVE-2016-6662CRITICALCVSS 9.8PoC≥ 5.5, < 5.5.51-38.1≥ 5.6, < 5.6.32-78.0+1 more2016-09-20
CVE-2016-6662 [CRITICAL] CWE-264 CVE-2016-6662: Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting genera
nvd