vendor:
MariaDB, Percona Server, MySQL
by:
Central InfoSec
7.2
CVSS
HIGH
OS Command Execution
78
CWE
Product Name: MariaDB, Percona Server, MySQL
Affected Version From: MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2021-27928
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2021-27928/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2021-27928/
Other Scripts:
N/A
Platforms Tested: Linux
2021
MariaDB 10.2 /MySQL – ‘wsrep_provider’ OS Command Execution
An OS command execution vulnerability exists in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An attacker can exploit this vulnerability by creating a reverse shell payload, starting a listener, copying the payload to the target machine, and executing the payload.
Mitigation:
Upgrade to MariaDB 10.2.37, 10.3.28, 10.4.18, and 10.5.9; Percona Server 2021-03-03; and the wsrep patch 2021-03-03 for MySQL.