CVE-2024-32886 MEDIUM

CVE-2024-32886: Vitess vulnerable to infinite memory consumption and vtgate crash

Vendor Vitessio
Product vitess
Weakness CWE-835
Published May 8, 2024
Last update August 2, 2024

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.

Key dates

02Disclosure timeline

May 8, 2024 CVE published
August 2, 2024 Record updated