Use After Poison Vulnerability in MariaDB Software
CVE-2022-32081

7.5HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
1 July 2022

What is CVE-2022-32081?

A use-after-poison vulnerability was found in MariaDB versions 10.4 to 10.7. This flaw occurs in the function prepare_inplace_add_virtual located in handler0alter.cc. An attacker exploiting this vulnerability could manipulate the state of the database, leading to potential unauthorized access or data corruption. Ensuring timely updates to the affected MariaDB versions is essential for maintaining database security.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.