MariaDB Connector/J 用于将使用 Java 开发的应用程序连接到 MariaDB 和 MySQL 数据库。在 2.7.14、3.3.5、3.4.3 和 3.5.9 之前版本中,PAM 对话框认证可能被强制在不安全的连接上传输账户密码。 插件要求通过安全传输(secure transport)进行门控,但其姊妹 PAM 处理器 (在服务器端被称为 dialog)并未声明这一要求,并继承了默认的“无需安全传输”(secure-required = false)设置;更早的分支中, 也实现了相同的行为。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mariadb-corporation | mariadb-connector-j | < 2.7.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55215 | 7.5 HIGH | MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: |
| CVE-2026-55855 | 6.5 MEDIUM | MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/ |
| CVE-2026-55854 | 5.9 MEDIUM | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficien |
| CVE-2026-55856 | 5.9 MEDIUM | MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-handshake |
| CVE-2026-55860 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clea |
| CVE-2026-55859 | 5.9 MEDIUM | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding o |
| CVE-2026-55858 | 5.9 MEDIUM | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mariadb |
No comments yet