CVE-2024-53257
Last modified
CVE-2024-53257 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template instead of rendering with a proper HTML templating engine. This vulnerability is fixed in 21.0.1, 20.0.4, and 19.0.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-53257?
How severe is CVE-2024-53257?
How do I fix CVE-2024-53257?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-53251Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-53252Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-53253Sentry is an error tracking and performance monitoring platf…5.3
- CVE-2024-53254Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2024-53255BoidCMS is a free and open-source flat file CMS for building…5.4
- CVE-2024-53256Rizin is a UNIX-like reverse engineering framework and comma…7.8
- CVE-2024-53258Autolab is a course management service that enables auto-gra…5.3
- CVE-2024-53259quic-go is an implementation of the QUIC protocol in Go. An …6.5
- CVE-2024-5326The Post Grid Gutenberg Blocks and WordPress Blog Plugin – P…8.8
- CVE-2024-53260Autolab is a course management service that enables auto-gra…6.8
- CVE-2024-53261SvelteKit is a framework for rapidly developing robust, perf…5.4
- CVE-2024-53262SvelteKit is a framework for rapidly developing robust, perf…5.4
Are you affected by CVE-2024-53257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
