Sploitus

CVE-2022-31011

No indexed exploits for CVE-2022-31011 yet

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.

Affected products
Tidb
Pingcap Tidb
= 5.3.0
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
0.3% (23th percentile)
Weakness
CWE-287
NVD status
Modified
Published
2022-05-31
CVE-2022-31011 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-31011 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-31011 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.