
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-14838 is a security vulnerability affecting the MySQL Server product, specifically in the Server: Security: Privileges component. The vulnerability was disclosed in October 2020 and affects multiple supported versions of MySQL Server (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 4.3 (MEDIUM) with the vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. This indicates a network-accessible vulnerability with low attack complexity, requiring low privileges, and no user interaction, potentially leading to unauthorized access to sensitive information (NetApp Security).
A successful exploitation of this vulnerability could allow an attacker to gain unauthorized read access to a subset of MySQL Server accessible data. The vulnerability specifically affects the privileges system within MySQL Server, potentially compromising the confidentiality of data (Oracle CPU Oct 2020).
The vulnerability requires network access and low privileges to exploit. It has been classified as having low attack complexity, indicating that it is relatively straightforward to exploit once an attacker has the necessary access (NetApp Security).
Oracle has released patches to address this vulnerability in MySQL versions 5.7.32 and 8.0.22. Users are strongly recommended to update to these versions or later. The patches are available through the October 2020 Critical Patch Update (Ubuntu Security Notice).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."