CVE-2017-15365
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.29% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- fedoraproject/fedora · mariadb/mariadb · percona/xtradb cluster
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2019:1258
- https://bugzilla.redhat.com/show_bug.cgi?id=1524234Issue Tracking, Third Party Advisory
- https://github.com/MariaDB/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46ePatch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ELCZV46WIYSJ6VMC65GMNN3A3QDRUJGK/
- https://mariadb.com/kb/en/library/mariadb-10130-release-notes/Release Notes, Vendor Advisory
- https://mariadb.com/kb/en/library/mariadb-10210-release-notes/Release Notes, Vendor Advisory
- https://www.debian.org/security/2018/dsa-4341
- https://www.percona.com/blog/2017/10/30/percona-xtradb-cluster-5-6-37-26-21-3-is-now-available/Release Notes, Vendor Advisory
- https://www.percona.com/doc/percona-xtradb-cluster/LATEST/release-notes/Percona-XtraDB-Cluster-5.7.19-29.22-3.htmlRelease Notes, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1258
- https://bugzilla.redhat.com/show_bug.cgi?id=1524234Issue Tracking, Third Party Advisory
- https://github.com/MariaDB/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46ePatch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ELCZV46WIYSJ6VMC65GMNN3A3QDRUJGK/
- https://mariadb.com/kb/en/library/mariadb-10130-release-notes/Release Notes, Vendor Advisory
- https://mariadb.com/kb/en/library/mariadb-10210-release-notes/Release Notes, Vendor Advisory
- https://www.debian.org/security/2018/dsa-4341
- https://www.percona.com/blog/2017/10/30/percona-xtradb-cluster-5-6-37-26-21-3-is-now-available/Release Notes, Vendor Advisory
- https://www.percona.com/doc/percona-xtradb-cluster/LATEST/release-notes/Percona-XtraDB-Cluster-5.7.19-29.22-3.htmlRelease Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.