← Back to CVE List

CVE-2022-21687

Published: 2022-02-01T12:15Z
Last Modified: 2024-11-21T06:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The attacker must have access to the target host or trick an administrator into executing a malicious gh-ost command on a host running gh-ost, plus network access from host running gh-ost to the attack's malicious MySQL server. The `-database` parameter does not properly sanitize user input which can lead to arbitrary file reads. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt