VulnerabilityModified
CVE-2022-26944
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.
MEDIUM 6.5EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table. NOTE: this issue exists because of an incomplete fix for CVE-2020-10997.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- percona/xtrabackup
- Source
- cve@mitre.org
References
- https://docs.percona.com/percona-xtrabackup/2.4/release-notes/2.4/2.4.25.htmlRelease Notes, Vendor Advisory
- https://jira.percona.com/browse/PXB-2722Permissions Required, Vendor Advisory
- https://docs.percona.com/percona-xtrabackup/2.4/release-notes/2.4/2.4.25.htmlRelease Notes, Vendor Advisory
- https://jira.percona.com/browse/PXB-2722Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.