
Cloud Vulnerability DB
A community-led vulnerabilities database
Percona XtraDB Backup versions >= 2.4.11 contained an information disclosure vulnerability (CVE-2020-10997) where command line arguments were exposed in multiple locations including backup files, process list, and standard error output. Additionally, when the --history argument was used, the command line was also captured in the PERCONA_SCHEMA.xtrabackup_history table (Percona Blog).
The vulnerability allows the exposure of command line arguments in multiple locations: 1) Within the resulting backup file location 2) In the PERCONA_SCHEMA.xtrabackup_history table when --history argument is used 3) In the process list 4) In standard error output. The issue was fixed in versions >= 2.4.20 and >= 8.0.11 (Percona Blog).
The impact of this vulnerability requires specific access conditions to be exploited: access to backup files, authenticated access to the MySQL server (when --history was used), or authenticated access to the Linux system/process list metadata to view command line arguments during execution (Percona Blog).
Exploitation of this vulnerability requires specific access conditions: 1) Access to backup files 2) Authenticated access to MySQL server (for --history related exposure) 3) Authenticated access to the Linux system or process list metadata. Protection of backup files and media is considered a best practice mitigation (Percona Blog).
The vulnerability has been patched in Percona XtraBackup versions >= 2.4.20 and >= 8.0.11. Users are advised to upgrade to these versions or later. Additionally, following security best practices for protecting backup files and media is recommended (Percona Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."