VDB

CVE-2023-39593

CVE-2023-39593 PUBLISHED CVSS 5.599999904632568 MEDIUM

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

EPSS 0.73% · 51.6th percentile

Risk Scores

CVSS 3.1
5.599999904632568
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
EPSS Score
0.73%
51.6th percentile

Affected Products

VendorProductVersions
Bitnamimariadb10.5.0
Bitnamimariadb10.5.0, 10.5.0, 10.5.0
Bitnamimariadb-min10.5.0
Bitnamimysql-client10.5.0, 10.5.0, 10.5.0
Bitnamimysql-client10.5.0
Bitnamimariadb-min10.5.0, 10.5.0, 10.5.0

Timeline

  • Oct 17, 2024 CVE Published
  • Oct 18, 2024 EPSS Score
  • Oct 20, 2024 CVE Updated
  • Nov 6, 2024 EPSS Score
  • Dec 14, 2024 EPSS Score
  • Jan 2, 2025 EPSS Score
  • Jan 21, 2025 EPSS Score
  • Feb 27, 2025 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 18, 2025 EPSS Score
  • Mar 20, 2025 EPSS Score
  • Mar 27, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›