Information Exposure The advisory has been revoked - it doesn't affect any version of package mysql  (opens in a new tab)


Threat Intelligence

EPSS
1.34% (68th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-MYSQL-2334169
  • published12 Jan 2022
  • disclosed5 Aug 2017
  • creditUnknown

Introduced: 5 Aug 2017

CVE-2017-12419  (opens in a new tab)
CWE-200  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Information Exposure. If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.