Security restrictions bypass in MySQL Connectors - CVE-2019-2435
Published: January 17, 2019
Vulnerability identifier: #VU17057
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2435
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The weakness exists due to unspecified flaw. A remote attacker may trick the victim into visiting a specially crafted website and bypass security restriction to read and modify potentially sensitive information.
The weakness exists due to unspecified flaw. A remote attacker may trick the victim into visiting a specially crafted website and bypass security restriction to read and modify potentially sensitive information.
Affected software
MySQL Connectors
Arch Linux
SUSE Linux
Opensuse
Juniper Junos Space
Arch Linux
SUSE Linux
Opensuse
Juniper Junos Space
How to mitigate CVE-2019-2435
Install update from vendor's website.
MySQL Connectors - update to 8.0.14
Juniper Junos Space - addressed in versions 20.3R1, 22.2R1
Juniper Junos Space - addressed in versions 20.3R1, 22.2R1
External References
Related Security Bulletins
- Security restrictions bypass in Oracle MySQL Connector
- Arch Linux update for python-mysql-connector
- OpenSUSE Linux update for python-mysql-connector-python
- OpenSUSE Linux update for python-mysql-connector-python
- Multiple vulnerabilities in Juniper Junos Space
- Multiple vulnerabilities in Junos Space
- Security restrictions bypass in MySQL Connectors