CVE Vulnerabilities

CVE-2017-15365

Published: Jan 25, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject26 (including)26 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mariadb102-galera-0:25.3.25-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-mariadb102-mariadb-1:10.2.22-1.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb102-galera-0:25.3.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-mariadb102-mariadb-1:10.2.22-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-mariadb102-galera-0:25.3.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSRedHatrh-mariadb102-mariadb-1:10.2.22-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-mariadb102-galera-0:25.3.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSRedHatrh-mariadb102-mariadb-1:10.2.22-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-mariadb102-galera-0:25.3.25-1.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSRedHatrh-mariadb102-mariadb-1:10.2.22-1.el7*
Mariadb-10.1Ubuntuartful*
Mariadb-10.1Ubuntucosmic*
Mariadb-10.1Ubuntuupstream*
Mariadb-10.1Ubuntuzesty*
Mysql-5.7Ubuntuartful*
Mysql-5.7Ubuntuzesty*
Percona-server-5.6Ubuntuartful*
Percona-server-5.6Ubuntuesm-apps/xenial*
Percona-server-5.6Ubuntuxenial*
Percona-server-5.6Ubuntuzesty*
Percona-xtradb-cluster-5.5Ubuntutrusty*
Percona-xtradb-cluster-5.6Ubuntuartful*
Percona-xtradb-cluster-5.6Ubuntuesm-apps/xenial*
Percona-xtradb-cluster-5.6Ubuntuxenial*
Percona-xtradb-cluster-5.6Ubuntuzesty*

References