tidbGHSA-7fxj-fr3v-r9gj
TiDB vulnerable to Use of Externally-Controlled Format String
Critical9.8CVE-2022-3023 · Published Nov 4, 2022 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/pingcap/tidb Go | <= 6.1.2 | No fix yet |
| >= 6.2.0, <= 6.4.0-alpha1 | No fix yet |
Details and references
TiDB server (importer CLI tool) prior to version 6.4.0 & 6.1.3 is vulnerable to data source name injection. The database name for generating and inserting data into a database does not properly sanitize user input which can lead to arbitrary file reads."
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-134
- Also known as
- CVE-2022-3023
More tidb advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 62022 | TiDB authentication bypass vulnerability CVE-2022-31011High7.8fixed in 0.0.0-20220221072141-27ffd1126da1, 1.1.0-beta.0.20220221072141-27ffd1126da1, 5.3.1 | High7.8 | 0.0.0-20220221072141-27ffd1126da1, 1.1.0-beta.0.20220221072141-27ffd1126da1, 5.3.1 |
| Jun 252024 | PingCAP TiDB nil pointer dereference CVE-2024-37820Medium5.4fixed in 8.2.0 | Medium5.4 | 8.2.0 |