Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-26944: Percona XtraBackup 2.4.25 — Percona XtraBackup 2.4 Documentation

Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table. NOTE: this issue exists because of an incomplete fix for CVE-2020-10997.

CVE
#sql#microsoft#git#c++

Date

April 26, 2022

Percona XtraBackup for MySQL Databases enables MySQL backups without blocking user queries. Percona XtraBackup is ideal for companies with large data sets and mission-critical applications that cannot tolerate long periods of downtime. Offered free as an open source solution, Percona XtraBackup drives down backup costs while providing unique features for MySQL backups.

Percona XtraBackup 2.4 does not support making backups of databases created in MySQL 8.0, Percona Server for MySQL 8.0, or Percona XtraDB Cluster 8.0. Use Percona XtraBackup 8.0 to make backups for these versions.

  • Release Highlights

  • New Features

  • Bugs Fixed

  • Useful Links

Release Highlights¶

The xbcloud binary adds support for the Microsoft Azure Cloud Storage using the REST API.

New Features¶

  • PXB-1883: Implements support for Microsoft Azure Cloud Storage in the xbcloud binary. (Thanks to Ivan Groenewold for reporting this issue)

Bugs Fixed¶

  • PXB-2608: Upgraded the Vault API to V2 (Thanks to Benedito Marques Magalhaes for reporting this issue)

  • PXB-2649: Fix for compilation issues on GCC-10.

  • PXB-2648: CURL prior to 7.38.0 version doesn’t use CURLE_HTTP2 and throws an error ‘CURLE_HTTP2’ is not a member of 'CURLcode’. Added CURLE_OBSOLETE16 as a connectivity error code. In CURL versions after 7.38.0, CURLE_OBSOLETE16 is translated to CURLE_HTTP2.

  • PXB-2711: Fix for libgcrypt initialization warnings in xtrabackup.

  • PXB-2722: Fix for when via command line, a password, passed using the -p option, was written into the backup tool_command in xtrabackup_info.

Useful Links¶

  • The Percona XtraBackup installation instructions

  • The Percona XtraBackup downloads

  • The Percona XtraBackup GitHub location

  • To contribute to the documentation, review the Documentation Contribution Guide

Related news

Gentoo Linux Security Advisory 202408-15

Gentoo Linux Security Advisory 202408-15 - Multiple vulnerabilities have been discovered in Percona XtraBackup, the worst of which could lead to arbitrary code execution. Versions greater than or equal to 8.0.29.22 are affected.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907