The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2017-09-28T19:00:00
Updated: 2024-08-06T04:33:19.329Z
Reserved: 2015-01-10T00:00:00
Link: CVE-2015-1027
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2017-09-29T01:34:47.907
Modified: 2025-04-20T01:37:25.860
Link: CVE-2015-1027
 Redhat
                        Redhat
                    No data.