Improper input validation in MySQL Connectors - CVE-2023-21971

 

Improper input validation in MySQL Connectors - CVE-2023-21971

Published: April 18, 2023


Vulnerability identifier: #VU75274
CSH Severity: Medium
CVSS v4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21971
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to read and manipulate data.

The vulnerability exists due to improper input validation within the Connector/J component in MySQL Connectors. A remote privileged user can exploit this vulnerability to read and manipulate data.


Affected software

MySQL Connectors
IBM Security Guardium
openSUSE Leap
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Policy
Keycloak
mysql-connector-java

How to mitigate CVE-2023-21971

Install updates from vendor's website.

Keycloak - update to 24.0.0
mysql-connector-java - addressed in versions 8.0.32-150200.3.15.1, 8.0.33-150200.3.18.1

External References

Related Security Bulletins