CVE-2023-39021
Java vulnerability analysis and mitigation

Overview

wix-embedded-mysql v4.6.1 and below contains a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. The vulnerability was discovered and disclosed on July 28, 2023, affecting the MySQL distribution setup functionality of the package. This vulnerability is tracked as CVE-2023-39021 and has been assigned a critical CVSS score of 9.8 (NVD).

Technical details

The vulnerability exists in the Setup.apply method within com.wix.mysql.distribution.Setup.java. The method is designed to set up MySQL but fails to properly validate input arguments, allowing for arbitrary command execution. The vulnerability can be exploited by passing an unchecked argument to the API through the IExtractedFileSet interface, specifically via the executable() method (GitHub POC).

Impact

If exploited, this vulnerability allows attackers to execute arbitrary code through the affected component. Given its CVSS score of 9.8, it is considered critical with potential for significant system compromise (NVD, FortiGuard).

Mitigation and workarounds

Users should avoid using versions 4.6.1 and below of wix-embedded-mysql. The recommended action is to upgrade to a version higher than 4.6.2. For those unable to upgrade immediately, implementing strict validation of IExtractedFileSet.executable() returns to ensure it only points to valid MySQL executable paths is suggested (FortiGuard).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26866HIGH8.8
  • JavaJava
  • org.apache.hugegraph:hg-pd-core
NoYesDec 12, 2025
CVE-2025-54981HIGH7.5
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-67721MEDIUM6.3
  • JavaJava
  • io.airlift:aircompressor-v3
NoYesDec 12, 2025
CVE-2025-53960MEDIUM5.9
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-54947MEDIUM5.3
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management