MySQL Server Vulnerability in Oracle MySQL Products
CVE-2025-21518

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2025

Summary

A vulnerability in the MySQL Server component of Oracle MySQL allows attackers with low privileges and network access to exploit the server via multiple protocols. A successful attack can lead to a denial of service, causing the MySQL Server to hang or crash repeatedly. This issue impacts supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior, thereby representing a significant security concern for users of affected MySQL products. For more information, refer to the Oracle Advisory.

Affected Version(s)

MySQL Cluster * <= 7.6.32

MySQL Cluster * <= 8.0.40

MySQL Cluster * <= 8.4.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.