Skip to content
tidbGHSA-7fxj-fr3v-r9gj

TiDB vulnerable to Use of Externally-Controlled Format String

Critical9.8CVE-2022-3023 · Published Nov 4, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/pingcap/tidb
Go
<= 6.1.2No fix yet
>= 6.2.0, <= 6.4.0-alpha1No fix yet
Details and references

TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-134
Also known as
CVE-2022-3023

More tidb advisories

All
DateAdvisory
Jun 62022TiDB authentication bypass vulnerability
CVE-2022-31011High7.8fixed in 0.0.0-20220221072141-27ffd1126da1, 1.1.0-beta.0.20220221072141-27ffd1126da1, 5.3.1
Jun 252024PingCAP TiDB nil pointer dereference
CVE-2024-37820Medium5.4fixed in 8.2.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.