Vulnerability Details CVE-2020-10997
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-10997
-
cpe:2.3:a:percona:xtrabackup:2.4.11
-
cpe:2.3:a:percona:xtrabackup:2.4.12
-
cpe:2.3:a:percona:xtrabackup:2.4.13
-
cpe:2.3:a:percona:xtrabackup:2.4.14
-
cpe:2.3:a:percona:xtrabackup:2.4.15
-
cpe:2.3:a:percona:xtrabackup:2.4.16
-
cpe:2.3:a:percona:xtrabackup:2.4.17
-
cpe:2.3:a:percona:xtrabackup:2.4.18
-
cpe:2.3:a:percona:xtrabackup:2.4.19
-
cpe:2.3:a:percona:xtrabackup:8.0.10
-
cpe:2.3:a:percona:xtrabackup:8.0.4
-
cpe:2.3:a:percona:xtrabackup:8.0.5
-
cpe:2.3:a:percona:xtrabackup:8.0.6
-
cpe:2.3:a:percona:xtrabackup:8.0.7
-
cpe:2.3:a:percona:xtrabackup:8.0.8
-
cpe:2.3:a:percona:xtrabackup:8.0.9