CVE-2021-27928
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
-Decision
Descriptions
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
Se detectó un problema de ejecución de código remota en MariaDB versiones 10.2 anteriores a 10.2.37, versiones 10.3 anteriores a 10.3.28, versiones 10.4 anteriores a 10.4.18 y versiones 10.5 anteriores a 10.5.9; Percona Server versiones hasta el 03-03-2021; y el parche de wsrep versiones hasta el 03-03-2021 para MySQL. Una ruta de búsqueda que no es confiable conlleva a una inyección eval, en la que un usuario SUPER de la base de datos puede ejecutar comandos del Sistema Operativo después de modificar las funciones wsrep_provider y wsrep_notify_cmd. NOTA: esto no afecta a un producto de Oracle
An update that solves four vulnerabilities and has two fixes is now available. This update for mariadb fixes the following issues. DML unspecified vulnerability lead to complete DOS. DML unspecified vulnerability can lead to complete DOS. InnoDB unspecified vulnerability lead to complete DOS. Fixed a remote code execution issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-03 CVE Reserved
- 2021-03-19 CVE Published
- 2021-04-14 First Exploit
- 2024-08-03 CVE Updated
- 2025-07-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2021/03/msg00028.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/162177 | 2021-04-14 | |
https://www.exploit-db.com/exploits/49765 | 2021-04-14 | |
https://github.com/Al1ex/CVE-2021-27928 | 2021-06-21 | |
https://github.com/shamo0/CVE-2021-27928-POC | 2021-12-09 | |
https://github.com/LalieA/CVE-2021-27928 | 2023-09-10 | |
http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.mariadb.org/browse/MDEV-25179 | 2022-05-03 | |
https://mariadb.com/kb/en/mariadb-10237-release-notes | 2022-05-03 | |
https://mariadb.com/kb/en/mariadb-10328-release-notes | 2022-05-03 | |
https://mariadb.com/kb/en/mariadb-10418-release-notes | 2022-05-03 | |
https://mariadb.com/kb/en/mariadb-1059-release-notes | 2022-05-03 | |
https://mariadb.com/kb/en/security | 2022-05-03 | |
https://security.gentoo.org/glsa/202105-28 | 2022-05-03 | |
https://access.redhat.com/security/cve/CVE-2021-27928 | 2021-05-19 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1940909 | 2021-05-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.2 < 10.2.37 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.2 < 10.2.37" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.3 < 10.3.28 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.3 < 10.3.28" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.4 < 10.4.18 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.4 < 10.4.18" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.5 < 10.5.9 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.5 < 10.5.9" | - |
Affected
| ||||||
Percona Search vendor "Percona" | Percona Server Search vendor "Percona" for product "Percona Server" | <= 2021-03-03 Search vendor "Percona" for product "Percona Server" and version " <= 2021-03-03" | - |
Affected
| ||||||
Galeracluster Search vendor "Galeracluster" | Wsrep Search vendor "Galeracluster" for product "Wsrep" | <= 2021-03-03 Search vendor "Galeracluster" for product "Wsrep" and version " <= 2021-03-03" | mysql |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|