Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-10997
Linux openSUSE vulnerability analysis and mitigation

Overview

Percona XtraDB Backup versions >= 2.4.11 contained an information disclosure vulnerability (CVE-2020-10997) where command line arguments were exposed in multiple locations including backup files, process list, and standard error output. Additionally, when the --history argument was used, the command line was also captured in the PERCONA_SCHEMA.xtrabackup_history table (Percona Blog).

Technical details

The vulnerability allows the exposure of command line arguments in multiple locations: 1) Within the resulting backup file location 2) In the PERCONA_SCHEMA.xtrabackup_history table when --history argument is used 3) In the process list 4) In standard error output. The issue was fixed in versions >= 2.4.20 and >= 8.0.11 (Percona Blog).

Impact

The impact of this vulnerability requires specific access conditions to be exploited: access to backup files, authenticated access to the MySQL server (when --history was used), or authenticated access to the Linux system/process list metadata to view command line arguments during execution (Percona Blog).

Exploitability

Exploitation of this vulnerability requires specific access conditions: 1) Access to backup files 2) Authenticated access to MySQL server (for --history related exposure) 3) Authenticated access to the Linux system or process list metadata. Protection of backup files and media is considered a best practice mitigation (Percona Blog).

Mitigation and workarounds

The vulnerability has been patched in Percona XtraBackup versions >= 2.4.20 and >= 8.0.11. Users are advised to upgrade to these versions or later. Additionally, following security best practices for protecting backup files and media is recommended (Percona Blog).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61548HIGH8.1
  • rsyslog logorsyslog
  • rsyslog-module-ossl
NoYesSep 18, 2026
CVE-2026-69184HIGH7.5
  • Node.js logoNode.js
  • nodejs22-debuginfo
NoYesSep 18, 2026
CVE-2026-54634HIGH7.3
  • Linux Debian logoLinux Debian
  • tcl-Hamlib
NoYesSep 17, 2026
CVE-2026-69186MEDIUM5.3
  • Linux Debian logoLinux Debian
  • c-ares-utils
NoYesSep 18, 2026
CVE-2026-48785MEDIUM4.8
  • Linux Debian logoLinux Debian
  • apptainer-sle15_6
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management