CVE-2020-10997
Percona XtraDB backup >= 2.4.11 suffers an issue whereby the
whole command line is captured and output to resulting backup
file location, and where –history command line argument is passed
this too is captured within the PERCONA_SCHEMA.xtrabackup_history
table. In addition to the information being present within the
process list and standard error output.
This issue is resolved in >= 2.4.20 and >= 8.0.11 .
Applicability
Access to backup files is required in order to exploit this
error, protection of backup files and media is already a well
known best-practise and we encourage our users to continue to
follow this practise.
Authenticated access to the MySQL server is required to collect
command line data where –history was used during backup.
Authenticated access to the Linux system on which PXB is being
executed or access to the Process …
[Read more]