CVE Vulnerabilities

CVE-2022-45347

Incomplete Cleanup

Published: Dec 22, 2022 | Modified: Dec 29, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didnt cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Shardingsphere Apache * 5.3.0 (excluding)

Potential Mitigations

References