Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37117.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-37117
Upstream
Published
2024-03-27T08:15:41Z
Modified
2026-04-01T05:13:12.494982Z
Summary
CVE-2024-2004 affecting package mysql for versions less than 8.0.40-1
Details

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.

References

Affected packages

Azure Linux:2 / mysql

Package

Name
mysql
Purl
pkg:rpm/azure-linux/mysql

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.40-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-37117.json"