MySQL Server Vulnerability in Oracle MySQL Product
CVE-2025-30721

4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability exists in the MySQL Server component of Oracle MySQL, affecting specific versions between 8.0.0 and 9.2.0. This vulnerability requires a logged-in user with high privileges to exploit. Attackers can cause a denial of service by inducing the server to hang or repeatedly crash, requiring interaction from someone other than the attacker for successful exploitation. Proper security measures should be taken by users of the affected MySQL Server versions to mitigate the risk.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.41

MySQL Server 8.4.0 <= 8.4.4

MySQL Server 9.0.0 <= 9.2.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.