Improper Input Validation
CVE-2023-29194
Summary
The vitess.io/vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing "/" characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using "vtctldclient GetKeyspaces" will also return an error. Note that all other keyspaces can still be administered using the CLI (vtctldclient). As a workaround, delete the offending keyspace using a CLI client (vtctldclient).This issue affects versions through 0.16.0 and 2.0.0-alpha1 through 16.0.0.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- HIGH
- NONE
- LOW
CWE-20 - Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
References
Advisory Timeline
- Published