Vulnerability Name:

CVE-2021-27928 (CCN-198521)

Assigned:2021-03-17
Published:2021-03-17
Updated:2022-05-03
Summary:A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd.
Note: this does not affect an Oracle product.
CVSS v3 Severity:7.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.8 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.2 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-94
CWE-78
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-27928

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html

Source: XF
Type: UNKNOWN
mariadb-cve202127928-cmd-exec(198521)

Source: CCN
Type: MDEV-25179
wsrep_provider and wsrep_notify_cmd system variables are writable

Source: MISC
Type: Issue Tracking, Vendor Advisory
https://jira.mariadb.org/browse/MDEV-25179

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210323 [SECURITY] [DLA 2605-1] mariadb-10.1 security update

Source: MISC
Type: Release Notes, Vendor Advisory
https://mariadb.com/kb/en/mariadb-10237-release-notes/

Source: MISC
Type: Release Notes, Vendor Advisory
https://mariadb.com/kb/en/mariadb-10328-release-notes/

Source: MISC
Type: Release Notes, Vendor Advisory
https://mariadb.com/kb/en/mariadb-10418-release-notes/

Source: MISC
Type: Release Notes, Vendor Advisory
https://mariadb.com/kb/en/mariadb-1059-release-notes/

Source: MISC
Type: Vendor Advisory
https://mariadb.com/kb/en/security/

Source: CCN
Type: MariaDB Web site
MariaDB

Source: CCN
Type: Packet Storm Security [04-14-2021]
MariaDB 10.2 Command Execution

Source: GENTOO
Type: Third Party Advisory
GLSA-202105-28

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [04-14-2021]

Source: CCN
Type: IBM Security Bulletin 6587431 (PowerVC)
PowerVC installation on RHEL is vulnerable to MariaDB with CVE-2021-27928

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 10.5 and < 10.5.9)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 10.4 and < 10.4.18)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 10.3 and < 10.3.28)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 10.2 and < 10.2.37)

  • Configuration 2:
  • cpe:/a:percona:percona_server:*:*:*:*:*:*:*:* (Version <= 2021-03-03)

  • Configuration 3:
  • cpe:/a:galeracluster:wsrep:*:*:*:*:*:mysql:*:* (Version <= 2021-03-03)

  • Configuration 4:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8044
    P
    netty3-3.10.6-150200.3.7.3 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7980
    P
    vino-3.22.0-150400.16.11 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51936
    P
    Security update for tiff (Important)
    2022-10-21
    oval:org.opensuse.security:def:6120
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:6119
    P
    Security update for json-c (Important) (in QA)
    2022-08-30
    oval:org.opensuse.security:def:95342
    P
    Security update for go1.18 (Important)
    2022-08-04
    oval:org.opensuse.security:def:95341
    P
    Security update for go1.17 (Important)
    2022-08-04
    oval:org.opensuse.security:def:6117
    P
    Security update for pcre2 (Important)
    2022-07-27
    oval:org.opensuse.security:def:3491
    P
    ft2demos-2.6.3-7.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95121
    P
    libmariadbd-devel-10.6.7-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112685
    P
    libmariadbd-devel-10.6.5-3.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99709
    P
    (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:100018
    P
    (Important)
    2021-11-22
    oval:org.opensuse.security:def:93110
    P
    (Moderate)
    2021-11-04
    oval:org.opensuse.security:def:125581
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:34500
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:89174
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:126750
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:23948
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:59519
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:5822
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:89432
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:127147
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:33696
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:59777
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:88169
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:33954
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:60323
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:88483
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:9008
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:92957
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:70265
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:109417
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:67208
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:102751
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:99119
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:10125
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:92361
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:69511
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:66882
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:9371
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:70451
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:67209
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:99311
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:10311
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:96061
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:8627
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:92560
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:5793
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:69701
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:108720
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:66883
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:102054
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:76276
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:9561
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:93263
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:91974
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:69069
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:111651
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:99510
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:75950
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:8813
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:92759
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:5794
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:69900
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:118513
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:108721
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:102055
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:76277
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:98924
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:9760
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:92169
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:111652
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:75951
    P
    Security update for mariadb (Important)
    2021-08-05
    oval:org.opensuse.security:def:76274
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:org.opensuse.security:def:102197
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:org.opensuse.security:def:111648
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:org.opensuse.security:def:1621
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:org.opensuse.security:def:67206
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:org.opensuse.security:def:69133
    P
    Security update for mariadb (Important)
    2021-08-04
    oval:com.redhat.rhsa:def:20211242
    P
    RHSA-2021:1242: mariadb:10.3 and mariadb-devel:10.3 security update (Important)
    2021-04-19
    BACK
    mariadb mariadb *
    mariadb mariadb *
    mariadb mariadb *
    mariadb mariadb *
    percona percona server *
    galeracluster wsrep *
    debian debian linux 9.0