{"id":"CVE-2023-29195","summary":"Vitess VTAdmin users that can create shards can deny access to other functions","details":"Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creating a shard using `vtctldclient` does not have the same problem because the CLI validates the input correctly. Version 16.0.2, corresponding to version 0.16.2 of the `go` module, contains a patch for this issue. Some workarounds are available. Always use `vtctldclient` to create shards, instead of using VTAdmin; disable creating shards from VTAdmin using RBAC; and/or delete the topology record for the offending shard using the client for your topology server.","aliases":["GHSA-pqj7-jx24-wj7w"],"modified":"2026-08-12T03:51:17.627041609Z","published":"2023-05-11T19:07:39.530Z","database_specific":{"cwe_ids":["CWE-20","CWE-703"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29195.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/vitessio/vitess/releases/tag/v16.0.2"},{"type":"WEB","url":"https://pkg.go.dev/vitess.io/vitess@v0.16.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/29xxx/CVE-2023-29195.json"},{"type":"ADVISORY","url":"https://github.com/vitessio/vitess/security/advisories/GHSA-pqj7-jx24-wj7w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29195"},{"type":"REPORT","url":"https://github.com/vitessio/vitess/issues/12842"},{"type":"FIX","url":"https://github.com/vitessio/vitess/commit/9dcbd7de3180f47e94f54989fb5c66daea00c920"},{"type":"FIX","url":"https://github.com/vitessio/vitess/pull/12843"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vitessio/vitess","events":[{"introduced":"0"},{"fixed":"6076fed0300de2eb7a17a5f5cd67527c29b5b3c6"},{"fixed":"9dcbd7de3180f47e94f54989fb5c66daea00c920"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"16.0.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:linuxfoundation:vitess:*:*:*:*:*:*:*:*"}}],"versions":["v16.0.1","v0.16.1","v16.0.0","v0.16.0","v16.0.0-rc1","v0.16.0-rc1","v10.0.0-rc1-mysql80","v10.0.0-rc1","v9.0.0-rc1","v8.0.0-rc1","v7.0.0-beta","v6.0.0-rc.1","v5.0.1","v5.0.0","v3.0.0-rc.3","v3.0","v3.0.0-rc.2","v3.0.0-rc.1","v2.2.0-rc.1","v2.2-alpha","v2.2","v2.1.0-alpha.1","v2.0.0-rc.2","v2.0.0-rc.1","v2.0.0-beta.2","v2.0.0-alpha5","v2.0.0-alpha4","v2.0.0-alpha2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-29195.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L"}]}