CVE-2026-55854
MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadb
Beschreibung
MariaDB Connector/Node.js wird verwendet, um Anwendungen, die mit Node.js entwickelt wurden, mit MariaDB- und MySQL-Datenbanken zu verbinden. Vor Versionen 3.2.4, 3.3.3, 3.4.6 und 3.5.3 kann der MariaDB Connector/Node.js bei Verhandlungen über ein unsicheres Transportmittel im Rahmen der PAM-Dialogauthentifizierung ein Benutzerkonto-Passwort preisgeben. In `lib/cmd/handshake/auth/pam-password-auth.js` und `lib/cmd/handshake/authentication.js` fehlte das sichere-Transport-Gatter für die Verhaltensweise von SendPamAuthPacketFactory im serverseitigen Plugin-Dialog, das auf mysql_clear_password angewendet wird. Mit den Standardeinstellungen `sslMode=DISABLE` und `restrictedAuth=null` kann ein bösartiger oder mitlaufender Server eine Anfrage zum Authentifizierungsschalter für einen Dialog über unverschlüsseltes TCP senden, wodurch der Connector das Konto-Passwort im Klartext zurückgibt. Eine ordnungsgemäß verifizierte TLS und ein lokaler Unix-Socket verhindern diesen Pfad, während eine nur auf Fingerabdruck basierende Server-Identitätsvalidierung nicht ausreichend ist. Dieses Problem wird in den Versionen 3.2.4, 3.3.3, 3.4.6 und 3.5.3 behoben.
Metriken
Weakness-Klassen (CWE)
CWE-319Base
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
cwe.mitre.org →CWE-522Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
cwe.mitre.org →
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
npm
mariadb3.3.0
npm
mariadb3.4.0
npm
mariadb3.5.0
npm
mariadb
Quellen & Referenzen
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-42r5-vhpq-m858x_refsource_CONFIRM
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/29733403cfe6519cdfe9c36c93765a468fbe285dx_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/53b304264df84496d331dba2765c3634602f342ex_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/9781de636841d34afdd08d81dd07d43edb82f85cx_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/fbc159c2c8bd18c2db2d2e6587ab3020bbda64b6x_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.4x_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.3x_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.6x_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.3x_refsource_MISC
- https://jira.mariadb.org/browse/CONJS-353x_refsource_MISC
- https://github.com/mariadb-corporation/mariadb-connector-nodejspackage
- https://nvd.nist.gov/vuln/detail/CVE-2026-55854web