Source: mysql-connector-python X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for mysql-connector-python. CVE-2024-21272[0]: | Vulnerability in the MySQL Connectors product of Oracle MySQL | (component: Connector/Python). Supported versions that are affected | are 9.0.0 and prior. Difficult to exploit vulnerability allows low | privileged attacker with network access via multiple protocols to | compromise MySQL Connectors. Successful attacks of this | vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 | Base Score 7.5 (Confidentiality, Integrity and Availability | impacts). CVSS Vector: | (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2024-21272 https://www.cve.org/CVERecord?id=CVE-2024-21272 Please adjust the affected versions in the BTS as needed.

