TiDB MySQL Protocol Vulnerability Issues

Note:
This topic has been translated from a Chinese forum by GPT and might contain errors.

Original topic: tidb mysql协议漏洞弄问题

| username: Lock4U

[TiDB Usage Environment] Production Environment / Testing / PoC
[TiDB Version]
[Reproduction Path] What operations were performed when the issue occurred
[Encountered Issue: Issue Phenomenon and Impact]
[Resource Configuration] Go to TiDB Dashboard - Cluster Info - Hosts and take a screenshot of this page
[Attachments: Screenshots/Logs/Monitoring]
Oracle MySQL is an open-source relational database management system developed by Oracle Corporation. MySQL Server is one of its database server components. The InnoDB subcomponent in MySQL Server versions 5.7.25 and earlier, and 8.0.15 and earlier, has a security vulnerability. Attackers can exploit this vulnerability to cause a denial of service (hang or frequent crashes), affecting data availability.

Experts, TiDB has now detected this kind of security vulnerability issue. Can upgrading TiDB solve it?

| username: Billmay表妹 | Original post link

Here’s a related post you can check out.

| username: tidb狂热爱好者 | Original post link

TiDB has no vulnerabilities.

| username: tidb菜鸟一只 | Original post link

Just skip it.

| username: zhanggame1 | Original post link

Ignore it.

| username: Lock4U | Original post link

Is this the correct format?

| username: tidb菜鸟一只 | Original post link

Well, after the modification, the version you configured will be scanned.

| username: TiDBer_CEVsub | Original post link

It’s safer to add a whitelist in the production environment, that way it won’t be scanned :face_with_peeking_eye:

| username: zhanggame1 | Original post link

According to the requirements of classified protection, important equipment still needs to be scanned.

| username: liuis | Original post link

Ignore~

| username: redgame | Original post link

The vulnerability direction is difficult to handle.

| username: Billmay表妹 | Original post link

The scanner’s detection is likely a false positive, so it can be ignored.

| username: system | Original post link

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.