Vulnerability Description
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | >= 10.1.0, < 10.1.47 |
| Debian | Debian Linux | 9.0 |
| Percona | Xtradb Cluster | < 5.6.49-28.42.2 |
| Galeracluster | Galera Cluster For Mysql | >= 5.6, < 5.6.49 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1894919Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00021.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202011-14Third Party Advisory
- https://www.debian.org/security/2020/dsa-4776Third Party Advisory
- https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-clPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1894919Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/10/msg00021.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202011-14Third Party Advisory
- https://www.debian.org/security/2020/dsa-4776Third Party Advisory
- https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-clPatchThird Party Advisory
FAQ
What is CVE-2020-15180?
CVE-2020-15180 is a vulnerability with a CVSS score of 9.0 (CRITICAL). A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary ...
How severe is CVE-2020-15180?
CVE-2020-15180 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-15180?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb, Debian Debian Linux, Percona Xtradb Cluster, Galeracluster Galera Cluster For Mysql.