sql/eventdataobjects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-15365.json"
[
{
"signature_type": "Function",
"source": "https://github.com/mariadb/server/commit/58e0dcb93dc2b2bf49f76c754bd216dbdf875a0d",
"id": "CVE-2017-15365-0500cd26",
"deprecated": false,
"target": {
"function": "os_file_set_size",
"file": "storage/innobase/os/os0file.cc"
},
"signature_version": "v1",
"digest": {
"length": 1930.0,
"function_hash": "229436509491359859587976164905941824146"
}
},
{
"signature_type": "Line",
"source": "https://github.com/mariadb/server/commit/58e0dcb93dc2b2bf49f76c754bd216dbdf875a0d",
"id": "CVE-2017-15365-6ad32b91",
"deprecated": false,
"target": {
"file": "storage/innobase/os/os0file.cc"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"199074947337376739812679047825821336002",
"46725345608552447089949872245821081371",
"119120488045980108076426049636030945131",
"58230573690248886038051992579509304232",
"326895143270909796380178638763687471280",
"263146896042637856319085632199764889177",
"122131190033688622756744393943115563446",
"133068113502970118870593079691731269775",
"111890012607856213573104663272595866488",
"61566547659338840586290761302690848319",
"313474223702629979055129385503607972230"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"source": "https://github.com/mariadb/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46e",
"id": "CVE-2017-15365-a325de97",
"deprecated": false,
"target": {
"file": "sql/event_data_objects.cc"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"9445645027427897318389279784351991844",
"87444934157594803502997278046451811121",
"168642665163784736974270184797232777216",
"82099996151664014416644330738062463880",
"272829302966075433290701918267687987954",
"53018175324844088271187787267686989289",
"306310327001560995259621411615300829613",
"138176057444522303513843507441557869369",
"110863210512714455066181538149603831554",
"162363930710182101563708158395046080095",
"216275540879309119547887464884848870991",
"326103304815071275075586492459181713480",
"5134074510500322221950659449014431694"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"source": "https://github.com/mariadb/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46e",
"id": "CVE-2017-15365-bbea56f3",
"deprecated": false,
"target": {
"function": "Event_job_data::execute",
"file": "sql/event_data_objects.cc"
},
"signature_version": "v1",
"digest": {
"length": 2993.0,
"function_hash": "92090847435171987634355350098869258426"
}
}
]
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "26"
}
]
},
{
"events": [
{
"introduced": "5.7.0"
},
{
"fixed": "5.7.19-29.22-3"
}
]
}
]