漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`
Vulnerability Description
Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI processes on the same host, to log in as the root user without a password when the service is used with mysql or percona-server. This issue is fixed in the 25.11 and 26.05.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
缺省权限不正确
Vulnerability Title
NixOS nixpkgs 权限许可和访问控制问题漏洞
Vulnerability Description
NixOS Nixpkgs是NixOS组织开源的一个 100000 多个软件包的集合。可以使用 Nix 包管理器安装。 NixOS nixpkgs 25.11之前版本和26.05之前版本存在权限许可和访问控制问题漏洞,该漏洞源于访问控制问题,导致MySQL services.mysql模块初始化数据库时,允许本地用户如未授权的Web或CGI进程以root用户身份无密码登录。
CVSS Information
N/A
Vulnerability Type
N/A