MySQL Server Vulnerability in Oracle MySQL Product
CVE-2025-30721
4MEDIUM
Summary
A vulnerability exists in the MySQL Server component of Oracle MySQL, affecting specific versions between 8.0.0 and 9.2.0. This vulnerability requires a logged-in user with high privileges to exploit. Attackers can cause a denial of service by inducing the server to hang or repeatedly crash, requiring interaction from someone other than the attacker for successful exploitation. Proper security measures should be taken by users of the affected MySQL Server versions to mitigate the risk.
Affected Version(s)
MySQL Server 8.0.0 <= 8.0.41
MySQL Server 8.4.0 <= 8.4.4
MySQL Server 9.0.0 <= 9.2.0
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved