Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-39593

Published: October 20, 2024Last modified: June 6, 2025

Description

Insecure permissions in the sys_exec function of Oracle MYSQL MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges.

Severity score breakdown

ParameterValue
Base score5.6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSmariadbUnknown (10.6.12-r0)
StreammariadbUnknown (10.11.4-r0)

References

ON THIS PAGE