Remote Code Execution (RCE) The advisory has been revoked - it doesn't affect any version of package MariaDB/server  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.73% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MARIADBSERVER-8235376
  • published22 Oct 2024
  • disclosed17 Oct 2024
  • creditUnknown

Introduced: 17 Oct 2024

CVE-2023-39593  (opens in a new tab)
CWE-94  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Remote Code Execution (RCE) by creating a malicious UDF via the sys_exec, sys_eval, sys_get, do_system, or sys_bineval functions.

Note: This is not considered a vulnerability by the maintainers because no privilege boundary is crossed.