Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-21209
Summary
A vulnerability exists in the MySQL Client component of Oracle MySQL, specifically affecting mysqldump. Supported versions impacted prior to 8.4.3, prior to 9.0.2. This vulnerability is challenging to exploit, requiring a high-privileged attacker with network access over multiple protocols and human interaction from a separate user. A successful attack could lead to unauthorized read access to certain data accessible within the MySQL Client.
- HIGH
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- HIGH
- LOW
- NONE
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
Advisory Timeline
- Published