CVE-2024-21054

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Apr 16, 2024
Updated: Jul 3, 2024
CWE ID 121

Summary

CVE-2024-21054 is a vulnerability affecting Oracle MySQL Server versions 8.0.36 and prior, as well as 8.3.0 and prior. This easily exploitable issue enables high privileged attackers with network access to compromise MySQL Server, leading to a denial of service (DoS) condition. Successful attacks may result in a hang or frequent crashes of MySQL Server, causing significant availability impacts. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System version 3.1, is 4.9. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MySQL
  • MySQL Server

Affected Vendors

  • BonqDAO
  • MySQL AB