Apache ShardingSphere-Proxy Incomplete Cleanup vulnerability
Critical severity
GitHub Reviewed
Published
Dec 22, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Package
Affected versions
< 5.3.0
Patched versions
5.3.0
Description
Published by the National Vulnerability Database
Dec 22, 2022
Published to the GitHub Advisory Database
Dec 22, 2022
Reviewed
Dec 22, 2022
Last updated
Feb 2, 2023
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.
References