天下漏洞,尽知其名
MEDIUM

CVE-2026-107819 MariaDB Connector/C 证书验证绕过漏洞

影响中间人可窃取数据库明文密码

AI 研判

MariaDB Connector/C 是用于连接 MariaDB 和 MySQL 数据库的 C/C++ 客户端库。在 3.4.1 至 3.4.10 之前的版本中,其 Zero-Configuration SSL 认证切换逻辑在校验证书信任失败后,未在选用非哈希认证插件前拒绝 TLS 主机名验证不匹配的情况。攻击者可借此绕过主机名校验并获取数据库密码。

影响范围

MariaDB Connector/C

MariaDB Connector/C 3.4.1 起至 3.4.10 之前的版本;其他 MariaDB 连接器不受影响。

漏洞详情

漏洞属于证书验证绕过(TLS 主机名校验缺失)。当 TLS 主机名与证书不匹配时,库未正确拒绝连接,而是继续选择非哈希认证插件。拥有其他主机名有效证书的中间人攻击者可请求 mysql_clear_password,从而在攻击者控制的 TLS 连接中获取数据库明文密码。

利用条件与风险

利用前提是攻击者能实施中间人攻击并持有其他主机名的有效证书,实战中可导致数据库凭据泄露,风险中等。

修复建议

升级至 MariaDB Connector/C 3.4.10 或更高版本;在无法升级时可临时避免使用 Zero-Configuration SSL 自动认证切换,或强制使用哈希认证插件并严格校验主机名。

原始情报

MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.