{"id":"MGASA-2020-0369","summary":"Updated mysql-connector-java package fixes security vulnerability","details":"A flaw was found in the mysql-connector-java package. A complicated attack\nagainst the mysql Connector/J allows attackers on the local network to\ninterfere with a user's connection and insert unauthorized SQL commands\n(CVE-2020-2934).\n","modified":"2026-04-16T04:43:06.744565323Z","published":"2020-09-21T19:45:58Z","upstream":["CVE-2020-2934"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0369.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26522"},{"type":"WEB","url":"https://dev.mysql.com/doc/relnotes/connector-j/8.0/en/news-8-0-20.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixMSQL"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/4QDR2WOUETBT76WAO5NNCCXSAM3AGG3D/"}],"affected":[{"package":{"name":"mysql-connector-java","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/mysql-connector-java?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.20-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0369.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}