Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
m3t3kh4n committed Oct 24, 2024
1 parent 55e9ec8 commit 1907466
Showing 1 changed file with 25 additions and 2 deletions.
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgjp-83m4-h4fj",
"modified": "2024-10-15T21:30:39Z",
"modified": "2024-10-16T18:31:40Z",
"published": "2024-10-15T21:30:39Z",
"aliases": [
"CVE-2024-21272"
],
"summary": "Access control bypass vulnerability in mysql-connector-python, affecting versions prior to 9.1.0, allowing low-privileged attackers with network access to compromise MySQL Connectors",
"details": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"severity": [
{
Expand All @@ -14,13 +15,35 @@
}
],
"affected": [

{
"package": {
"ecosystem": "PyPI",
"name": "mysql-connector-python"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "9.1.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21272"
},
{
"type": "PACKAGE",
"url": "https://pypi.org/project/mysql-connector-python"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2024.html"
Expand Down

0 comments on commit 1907466

Please sign in to comment.