{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Copyright 2023 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"Security update for mysql-connector-java","title":"Title of the patch"},{"category":"description","text":"This update for mysql-connector-java fixes the following issues:\n\n- CVE-2023-21971: Fixed a denial-of-service vulnerability in the java.sql.DriverManager.getConnection() method when used with untrusted inputs (bsc#1211247).\n","title":"Description of the patch"},{"category":"details","text":"SUSE-2023-2979,openSUSE-SLE-15.4-2023-2979,openSUSE-SLE-15.5-2023-2979","title":"Patchnames"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"self","summary":"URL for SUSE-SU-2023:2979-1","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232979-1/"},{"category":"external","summary":"SUSE ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"self","summary":"URL of this CSAF notice","url":"https://ftp.suse.com/pub/projects/security/csaf/suse-su-2023_2979-1.json"},{"category":"self","summary":"E-Mail link for SUSE-SU-2023:2979-1","url":"https://lists.suse.com/pipermail/sle-security-updates/2023-July/015640.html"},{"category":"self","summary":"SUSE Bug 1211247","url":"https://bugzilla.suse.com/1211247"},{"category":"self","summary":"SUSE CVE CVE-2023-21971 page","url":"https://www.suse.com/security/cve/CVE-2023-21971/"}],"title":"Security update for mysql-connector-java","tracking":{"current_release_date":"2023-07-26T07:57:49Z","generator":{"date":"2023-07-26T07:57:49Z","engine":{"name":"cve-database.git:bin/generate-csaf.pl","version":"1"}},"id":"SUSE-SU-2023:2979-1","initial_release_date":"2023-07-26T07:57:49Z","revision_history":[{"date":"2023-07-26T07:57:49Z","number":"1","summary":"Current version"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"mysql-connector-java-8.0.33-150200.3.18.1.noarch","product":{"name":"mysql-connector-java-8.0.33-150200.3.18.1.noarch","product_id":"mysql-connector-java-8.0.33-150200.3.18.1.noarch"}}],"category":"architecture","name":"noarch"},{"branches":[{"category":"product_name","name":"openSUSE Leap 15.4","product":{"name":"openSUSE Leap 15.4","product_id":"openSUSE Leap 15.4","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.4"}}},{"category":"product_name","name":"openSUSE Leap 15.5","product":{"name":"openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.5"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"mysql-connector-java-8.0.33-150200.3.18.1.noarch as component of openSUSE Leap 15.4","product_id":"openSUSE Leap 15.4:mysql-connector-java-8.0.33-150200.3.18.1.noarch"},"product_reference":"mysql-connector-java-8.0.33-150200.3.18.1.noarch","relates_to_product_reference":"openSUSE Leap 15.4"},{"category":"default_component_of","full_product_name":{"name":"mysql-connector-java-8.0.33-150200.3.18.1.noarch as component of openSUSE Leap 15.5","product_id":"openSUSE Leap 15.5:mysql-connector-java-8.0.33-150200.3.18.1.noarch"},"product_reference":"mysql-connector-java-8.0.33-150200.3.18.1.noarch","relates_to_product_reference":"openSUSE Leap 15.5"}]},"vulnerabilities":[{"cve":"CVE-2023-21971","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2023-21971"}],"notes":[{"category":"general","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as  unauthorized update, insert or delete access to some of MySQL Connectors accessible data and  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).","title":"Vulnerability description"}],"product_status":{"fixed":["openSUSE Leap 15.4:mysql-connector-java-8.0.33-150200.3.18.1.noarch","openSUSE Leap 15.5:mysql-connector-java-8.0.33-150200.3.18.1.noarch"]},"references":[{"category":"external","summary":"CVE-2023-21971","url":"https://www.suse.com/security/cve/CVE-2023-21971"},{"category":"external","summary":"SUSE Bug 1211247 for CVE-2023-21971","url":"https://bugzilla.suse.com/1211247"},{"category":"external","summary":"SUSE Bug 1212040 for CVE-2023-21971","url":"https://bugzilla.suse.com/1212040"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Leap 15.4:mysql-connector-java-8.0.33-150200.3.18.1.noarch","openSUSE Leap 15.5:mysql-connector-java-8.0.33-150200.3.18.1.noarch"]}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H","version":"3.1"},"products":["openSUSE Leap 15.4:mysql-connector-java-8.0.33-150200.3.18.1.noarch","openSUSE Leap 15.5:mysql-connector-java-8.0.33-150200.3.18.1.noarch"]}],"threats":[{"category":"impact","date":"2023-07-26T07:57:49Z","details":"moderate"}],"title":"CVE-2023-21971"}]}