REDHAT-BUG-2488451: High severity MariaDB MariaDB Server vulnerability
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 10.6.26 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 10.11.17 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 11.4.11 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 11.8.7 - Upgrade
Upgrade
MariaDBto a version that resolves this vulnerability.Fixed in 12.3.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2488451?
The severity of REDHAT-BUG-2488451 is high with a score of 7.
How do I fix REDHAT-BUG-2488451?
To fix REDHAT-BUG-2488451, upgrade MariaDB to versions 10.6.26 or later, 10.11.17 or later, 11.4.11 or later, 11.8.7 or later, or 12.3.1 or later.
What versions are affected by REDHAT-BUG-2488451?
Versions of MariaDB affected by REDHAT-BUG-2488451 include 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1.
What is the main issue described in REDHAT-BUG-2488451?
The main issue in REDHAT-BUG-2488451 involves the interpolation of the table HTTP attribute when using the CONNECT engine with REST support enabled on Windows.
Is REDHAT-BUG-2488451 specific to any platforms?
Yes, REDHAT-BUG-2488451 is specifically affecting the MariaDB server on Windows.