CVE-2020-10997
Linux openSUSE vulnerability analysis and mitigation

Overview

Percona XtraDB Backup versions >= 2.4.11 contained an information disclosure vulnerability (CVE-2020-10997) where command line arguments were exposed in multiple locations including backup files, process list, and standard error output. Additionally, when the --history argument was used, the command line was also captured in the PERCONA_SCHEMA.xtrabackup_history table (Percona Blog).

Technical details

The vulnerability allows the exposure of command line arguments in multiple locations: 1) Within the resulting backup file location 2) In the PERCONA_SCHEMA.xtrabackup_history table when --history argument is used 3) In the process list 4) In standard error output. The issue was fixed in versions >= 2.4.20 and >= 8.0.11 (Percona Blog).

Impact

The impact of this vulnerability requires specific access conditions to be exploited: access to backup files, authenticated access to the MySQL server (when --history was used), or authenticated access to the Linux system/process list metadata to view command line arguments during execution (Percona Blog).

Exploitability

Exploitation of this vulnerability requires specific access conditions: 1) Access to backup files 2) Authenticated access to MySQL server (for --history related exposure) 3) Authenticated access to the Linux system or process list metadata. Protection of backup files and media is considered a best practice mitigation (Percona Blog).

Mitigation and workarounds

The vulnerability has been patched in Percona XtraBackup versions >= 2.4.20 and >= 8.0.11. Users are advised to upgrade to these versions or later. Additionally, following security best practices for protecting backup files and media is recommended (Percona Blog).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-devel
NoYesSep 10, 2026
CVE-2026-57825MEDIUM5.7
  • Linux Debian logoLinux Debian
  • opam
NoYesSep 09, 2026
CVE-2026-77159MEDIUM5.5
  • Linux Debian logoLinux Debian
  • libvirt-daemon-driver-storage-logical
NoYesSep 11, 2026
CVE-2026-84445HIGHN/A
  • cAdvisor logocAdvisor
  • paketo-buildpacks-miniconda-0.11.35
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management