CVE-2025-21520

Updated: 2025-11-10 00:26:40.739761

Description:

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x LOW 1.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU mysql 8.0.32 1.8 LOW Released CLSA-2025:1741637440 2025-03-10 22:58:09
Alpine Linux 3.18 ELS mysql 10.11.11 1.8 LOW Ignored 2025-09-08 14:52:18 Ignored due to low severity
CentOS 6 ELS mysql 5.1.73 1.8 LOW Ignored 2025-04-18 03:52:32 Ignored due to low severity score
CentOS 8.4 ELS mysql 8.0.26 1.8 LOW Released CLSA-2025:1740823577 2025-03-01 23:38:40
CentOS 8.5 ELS mysql 8.0.26 1.8 LOW Released CLSA-2025:1740824456 2025-03-01 23:38:40
CentOS Stream 8 ELS mysql 8.0.26 1.8 LOW Released CLSA-2025:1741074282 2025-03-04 21:54:27
CloudLinux 6 ELS mysql 5.1.73 1.8 LOW Ignored 2025-04-18 03:52:32 Out of support scope
Oracle Linux 6 ELS mysql 5.1.73 1.8 LOW Ignored 2025-04-18 03:52:32 Ignored due to low severity score
Ubuntu 20.04 ELS mysql 8.0.41 1.8 LOW Ignored 2025-04-19 03:59:08 Ignored due to low severity