Impact
This vulnerability resides in the Server: Clone Plugin of Oracle MySQL. It can allow an attacker who obtains high privileges and network access to cause a hang or repeatable crash of the MySQL Server or MySQL Cluster, resulting in a full denial of service. The exploit requires the attacker to interact with the clone function over one of MySQL’s supported network protocols. The impact is limited to availability; confidentiality and integrity are not affected.
Affected Systems
Affected are Oracle’s MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. All installations of those products that have the Clone Plugin enabled are susceptible.
Risk and Exploitability
The CVSS 3.1 base score is 4.4, indicating a moderate availability risk. The EPSS score is less than 1%, implying a very low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. A high‑privileged attacker with network reach to MySQL services can trigger the flaw to interrupt database availability, but no known remote code execution or data disclosure is possible according to the current advisory.
OpenCVE Enrichment