CVE-2021-2372

Public on 2021-07-21
Modified on 2024-01-19
Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.

This issue requires that the attacker have privileges to access the target database. Considering the tradeoff between the stability of Amazon Linux and the impact of CVE-2021-2372 and CVE-2021-2389 a fix will not be provided for mariadb-5.5 in Amazon Linux 2 at this time.

Severity
Medium
See what this means
CVSS v3 Base Score
4.4
See breakdown

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Mariadb10.5 Extra mariadb 2023-08-21 21:00 ALAS2MARIADB10.5-2023-003
Amazon Linux 2023 mariadb105 2023-02-17 20:44 ALAS2023-2023-037
Amazon Linux 1 mysql57 2021-10-29 16:27 ALAS-2021-1544

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv2 3.5 AV:N/AC:M/Au:S/C:N/I:N/A:P
NVD CVSSv3 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H