CVE-2022-3023Critical· 9.8▾ MidnightTiDB vulnerable to Use of Externally-Controlled Format String
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
0.6% → 0.6%
Last analysed / modified upstream
TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."
github.com/pingcap/tidb <= 6.1.2github.com/pingcap/tidb >= 6.2.0, <= 6.4.0-alpha1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.