Incorrect Permission Assignment for Critical Resource
CVE-2025-30688
Summary
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). An easily exploitable vulnerability allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or a frequently repeatable crash (complete DoS) of MySQL Server. This issue affects mysql-server versions 8.0.0 through 8.0.41, 8.4.0 through 8.4.4, and 9.0.0-release through 9.2.0.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- NONE
- HIGH
CWE-732 - Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Advisory Timeline
- Published