CVE-2020-15180: Debian Linux

Critical severity, CVSS 9.0. EPSS: 5.5% chance of exploitation in the next 30 days.

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Galeracluster Galera Cluster For MySQL: from 5.6, before 5.6.49 (fixed in 5.6.49); from 5.7, before 5.7.31 (fixed in 5.7.31); from 8.0, before 8.0.21 (fixed in 8.0.21)
  • MariaDB MariaDB: from 10.1.0, before 10.1.47 (fixed in 10.1.47); from 10.2.0, before 10.2.34 (fixed in 10.2.34); from 10.3.0, before 10.3.25 (fixed in 10.3.25); from 10.4.0, before 10.4.15 (fixed in 10.4.15); from 10.5.0, before 10.5.6 (fixed in 10.5.6)
  • Percona Xtradb Cluster: before 5.6.49-28.42.2 (fixed in 5.6.49-28.42.2); from 5.7, before 5.7.31-31.45.2 (fixed in 5.7.31-31.45.2); from 8.0, before 8.0.20-11.2 (fixed in 8.0.20-11.2)

Published 2021-05-27. Last modified 2026-06-17.