Skip to main content

Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-21209

Severity Low
Score 2/10

Summary

A vulnerability exists in the MySQL Client component of Oracle MySQL, specifically affecting mysqldump. Supported versions impacted prior to 8.4.3, prior to 9.0.2. This vulnerability is challenging to exploit, requiring a high-privileged attacker with network access over multiple protocols and human interaction from a separate user. A successful attack could lead to unauthorized read access to certain data accessible within the MySQL Client.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • HIGH
  • LOW
  • NONE

CWE-200 - Information Exposure

An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.

Advisory Timeline

  • Published