CVE-2020-10997: Percona Xtrabackup
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table.
Affected products
- Percona Xtrabackup: from 2.4.11, before 2.4.20 (fixed in 2.4.20); from 8.0.4, before 8.0.11 (fixed in 8.0.11)
Published 2020-04-27. Last modified 2026-06-17.