漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
vitess allows users to create keyspaces that can deny access to already existing keyspaces
Vulnerability Description
Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list all the keyspaces using `vtctldclient GetKeyspaces` will also return an error. Note that all other keyspaces can still be administered using the CLI (vtctldclient). This issue is fixed in version 16.0.1. As a workaround, delete the offending keyspace using a CLI client (vtctldclient).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L
Vulnerability Type
输入验证不恰当
Vulnerability Title
Vitess 安全漏洞
Vulnerability Description
Vitess是Vitess的一个用于水平扩展 MySQL 的数据库集群系统。 Vitess 16.0.1之前版本存在安全漏洞,该漏洞源于任何试图从VTAdmin查看键空间的人都会收到错误消息。
CVSS Information
N/A
Vulnerability Type
N/A