Intel

AIKIDO-2025-10068

mysql-connector-java is vulnerable to Remote code execution

Remote code executionCVE-2023-22102 Published Feb 3, 2025

75

High Risk

This Affects:

JAVAmysql-connector-java
0.0.1 - 8.0.33
Are you affected? Scan for Free

TL;DR

MySQL Connectors takeover vulnerability

Who does this affect?

Attacker must have network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker.

Background info

mysql-connector-java is vulnerable to Remote code execution in versions 0.0.1 - 8.0.33.

How to fix this

The namespace of this package has been changed on Maven to https://mvnrepository.com/artifact/com.mysql/mysql-connector-j. Upgrade to at least version 8.2.0 of this new package.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform