CVE Published: 22/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache ShardingSphere-Proxy Status : PUBLISHED
CVE-2022-45347 Description
Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn\'t cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has been fixed in Apache ShardingSphere 5.3.0.