Loading HuntDB...

GHSA-hgjp-83m4-h4fj

GitHub Security Advisory

MySQL Connector/Python connector takeover vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Affected Packages

PyPI mysql-connector-python
Affected versions: 0 (fixed in 9.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-hgjp-83m4-h4fj
Published
October 15, 2024 9:30 PM
Last Modified
October 24, 2024 4:45 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
mysql-connector-python
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:21 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.