CVE-2020-15180
9.0
CRITICAL · CVSS 3.1 · EPSS 5.5% (pctl 93)
In your normal cycle
Critical by CVSS (9), but no sign of active exploitation.
Description
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 5.54% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-05-27 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| debian | debian linux |
| galeracluster | galera cluster for mysql |
| mariadb | mariadb |
| percona | xtradb cluster |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1894919
- https://lists.debian.org/debian-lts-announce/2020/10/msg00021.html
- https://security.gentoo.org/glsa/202011-14
- https://www.debian.org/security/2020/dsa-4776
- https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-cluster/
- https://bugzilla.redhat.com/show_bug.cgi?id=1894919
- https://lists.debian.org/debian-lts-announce/2020/10/msg00021.html
- https://security.gentoo.org/glsa/202011-14
- https://www.debian.org/security/2020/dsa-4776
- https://www.percona.com/blog/2020/10/30/cve-2020-15180-affects-percona-xtradb-cluster/
→ the Explorer · watch your stack · NVD