Denial of Service Vulnerability in MySQL Cluster by Oracle
CVE-2025-30710

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

The MySQL Cluster product by Oracle is susceptible to a Denial of Service vulnerability through the NDBCluster Plugin. This weakness allows an attacker with high privileges and network access to exploit the MySQL Cluster, potentially leading to frequent crashes or hangs. Affected versions include 8.0.0 to 8.0.41, 8.4.0 to 8.4.4, and 9.0.0 to 9.2.0. Organizations using these versions should take immediate action to secure their systems.

Affected Version(s)

MySQL Cluster 8.0.0 <= 8.0.41

MySQL Cluster 8.4.0 <= 8.4.4

MySQL Cluster 9.0.0 <= 9.2.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.