Vulnerability record · CVE-2023-29195 · published 11 May 2023
CVE-2023-29195: Linuxfoundation vitess improper input validation vulnerability
Linuxfoundation · Vitess
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creating a shard using `vtctldclient` does not have the same problem because the CLI validates the input correctly. Version 16.0.2, corresponding to version 0.16.2 of the `go` module, contains a patch for this issue. Some workarounds are available. Always use `vtctldclient` to create shards, instead of using VTAdmin; disable creating shards from VTAdmin using RBAC; and/or delete the topology record for the offending shard using the client for your topology server.
Description
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to create a new shard from VTAdmin will receive an error. Attempting to view the keyspace(s) will also no longer work. Creating a shard using `vtctldclient` does not have the same problem because the CLI validates the input correctly. Version 16.0.2, corresponding to version 0.16.2 of the `go` module, contains a patch for this issue. Some workarounds are available. Always use `vtctldclient` to create shards, instead of using VTAdmin; disable creating shards from VTAdmin using RBAC; and/or delete the topology record for the offending shard using the client for your topology server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/vitessio/vitess/commit/9dcbd7de3180f47e94f54989fb5c66daea00c920 | Patch |
| https://github.com/vitessio/vitess/issues/12842 | ExploitIssue TrackingPatch |
| https://github.com/vitessio/vitess/pull/12843 | Issue TrackingPatch |
| https://github.com/vitessio/vitess/releases/tag/v16.0.2 | Release Notes |
| https://github.com/vitessio/vitess/security/advisories/GHSA-pqj7-jx24-wj7w | MitigationVendor Advisory |
| https://pkg.go.dev/vitess.io/[email protected] | Product |
| https://github.com/vitessio/vitess/commit/9dcbd7de3180f47e94f54989fb5c66daea00c920 | Patch |
| https://github.com/vitessio/vitess/issues/12842 | ExploitIssue TrackingPatch |
| https://github.com/vitessio/vitess/pull/12843 | Issue TrackingPatch |
| https://github.com/vitessio/vitess/releases/tag/v16.0.2 | Release Notes |
| https://github.com/vitessio/vitess/security/advisories/GHSA-pqj7-jx24-wj7w | MitigationVendor Advisory |
| https://pkg.go.dev/vitess.io/[email protected] | Product |
Track CVE-2023-29195 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29195), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.