apache / apache/incubator-seata

CVE-2023-22102:8.9/10 :MySQL Connectors takeover vulnerability

Open
#8,101 3 comments 0 reactions 0 assignees View on GitHub
good first issue task: help-wanted
Dominant language
Java
Stars
26k
Forks
8.8k
Avg merge
1d 8h
Merged PRs (30d)
4

Description

### Check Ahead

- [x] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.

- [ ] I am willing to try to fix this bug myself.

### Ⅰ. Issue Description

https://github.com/advisories/GHSA-m6vm-37g8-gqvh

### Ⅱ. Describe what happened

_No response_

### Ⅲ. Describe what you expected to happen

_No response_

### Ⅳ. How to reproduce it (as minimally and precisely as possible)

_No response_

### Ⅴ. Anything else we need to know?

_No response_

### Ⅵ. Environment

_No response_

Contributor guide

Open the contributing guide

Research direction

The issue provides only the GHSA-m6vm-37g8-gqvh advisory and names no repository file, test, reproduction, or expected change. Start by reading the linked advisory and determining whether this repository includes the affected MySQL Connector; completion would require a clearly identified remediation and verification, neither of which is specified here.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, mysql
Domain
databases, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.