{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"mysql security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for mysql is now available for openEuler-22.03-LTS-SP1",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"The MySQL(TM) software delivers a very fast, multi-threaded, multi-user, and robust SQL (Structured Query Language) database server. MySQL Server is intended for mission-critical, heavy-load production systems as well as for embedding into mass-deployed software. MySQL is a trademark of Oracle and/or its affiliates\n\nSecurity Fix(es):\n\nThe public API function BIO_new_NDEF is a helper function used for streaming\nASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the\nSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by\nend user applications.\n\nThe function receives a BIO from the caller, prepends a new BIO_f_asn1 filter\nBIO onto the front of it to form a BIO chain, and then returns the new head of\nthe BIO chain to the caller. Under certain conditions, for example if a CMS\nrecipient public key is invalid, the new filter BIO is freed and the function\nreturns a NULL result indicating a failure. However, in this case, the BIO chain\nis not properly cleaned up and the BIO passed by the caller still retains\ninternal pointers to the previously freed filter BIO. If the caller then goes on\nto call BIO_pop() on the BIO then a use-after-free will occur. This will most\nlikely result in a crash.\n\n\n\nThis scenario occurs directly in the internal function B64_write_ASN1() which\nmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() on\nthe BIO. This internal function is in turn called by the public API functions\nPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,\nSMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.\n\nOther public API functions that may be impacted by this include\ni2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream and\ni2d_PKCS7_bio_stream.\n\nThe OpenSSL cms and smime command line applications are similarly affected.\n\n\n\n(CVE-2023-0215)\n\nThis flaw makes curl overflow a heap based buffer in the SOCKS5 proxy\nhandshake.\n\nWhen curl is asked to pass along the host name to the SOCKS5 proxy to allow\nthat to resolve the address instead of it getting done by curl itself, the\nmaximum length that host name can be is 255 bytes.\n\nIf the host name is detected to be longer, curl switches to local name\nresolving and instead passes on the resolved address only. Due to this bug,\nthe local variable that means \"let the host resolve the name\" could get the\nwrong value during a slow SOCKS5 handshake, and contrary to the intention,\ncopy the too long host name to the target buffer instead of copying just the\nresolved address there.\n\nThe target buffer being a heap based buffer, and the host name coming from the\nURL that curl has been told to operate with.\n(CVE-2023-38545)\n\nVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.35 and prior and  8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2024-21137)\n\nVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2024-21159)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for mysql is now available for openEuler-22.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"mysql",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2024-2072",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2072"
			},
			{
				"summary":"CVE-2023-0215",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2023-0215&packageName=mysql"
			},
			{
				"summary":"CVE-2023-38545",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2023-38545&packageName=mysql"
			},
			{
				"summary":"CVE-2024-21137",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-21137&packageName=mysql"
			},
			{
				"summary":"CVE-2024-21159",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-21159&packageName=mysql"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0215"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38545"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21137"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21159"
			},
			{
				"summary":"openEuler-SA-2024-2072 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openeuler-sa-2024-2072.json"
			}
		],
		"title":"An update for mysql is now available for openEuler-22.03-LTS-SP1",
		"tracking":{
			"initial_release_date":"2024-08-30T20:25:29+08:00",
			"revision_history":[
				{
					"date":"2024-08-30T20:25:29+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2024-08-30T20:25:29+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2024-08-30T20:25:29+08:00",
			"id":"openEuler-SA-2024-2072",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"openEuler-22.03-LTS-SP1",
									"name":"openEuler-22.03-LTS-SP1"
								},
								"name":"openEuler-22.03-LTS-SP1",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-common-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-common-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-common-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-config-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-config-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-config-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-debugsource-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-debugsource-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-debugsource-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-devel-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-devel-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-devel-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-errmsg-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-errmsg-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-errmsg-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-help-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-help-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-help-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-libs-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-libs-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-libs-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-server-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-server-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-server-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-test-8.0.38-1.oe2203sp1.aarch64.rpm",
									"name":"mysql-test-8.0.38-1.oe2203sp1.aarch64.rpm"
								},
								"name":"mysql-test-8.0.38-1.oe2203sp1.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-8.0.38-1.oe2203sp1.src.rpm",
									"name":"mysql-8.0.38-1.oe2203sp1.src.rpm"
								},
								"name":"mysql-8.0.38-1.oe2203sp1.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-common-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-common-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-common-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-config-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-config-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-config-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-debugsource-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-debugsource-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-debugsource-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-devel-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-devel-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-devel-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-errmsg-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-errmsg-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-errmsg-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-help-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-help-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-help-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-libs-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-libs-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-libs-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-server-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-server-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-server-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
									},
									"product_id":"mysql-test-8.0.38-1.oe2203sp1.x86_64.rpm",
									"name":"mysql-test-8.0.38-1.oe2203sp1.x86_64.rpm"
								},
								"name":"mysql-test-8.0.38-1.oe2203sp1.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-common-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-common-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-config-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-config-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-debugsource-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-debugsource-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-devel-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-devel-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-errmsg-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-errmsg-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-help-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-help-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-libs-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-libs-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-server-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-server-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-test-8.0.38-1.oe2203sp1.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
					"name":"mysql-test-8.0.38-1.oe2203sp1.aarch64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-8.0.38-1.oe2203sp1.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
					"name":"mysql-8.0.38-1.oe2203sp1.src as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-common-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-common-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-config-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-config-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-debugsource-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-debugsource-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-devel-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-devel-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-errmsg-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-errmsg-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-help-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-help-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-libs-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-libs-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-server-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-server-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
				"product_reference":"mysql-test-8.0.38-1.oe2203sp1.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64",
					"name":"mysql-test-8.0.38-1.oe2203sp1.x86_64 as a component of openEuler-22.03-LTS-SP1"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2023-0215",
			"notes":[
				{
					"text":"The public API function BIO_new_NDEF is a helper function used for streamingASN.1 data via a BIO. It is primarily used internally to OpenSSL to support theSMIME, CMS and PKCS7 streaming capabilities, but may also be called directly byend user applications.The function receives a BIO from the caller, prepends a new BIO_f_asn1 filterBIO onto the front of it to form a BIO chain, and then returns the new head ofthe BIO chain to the caller. Under certain conditions, for example if a CMSrecipient public key is invalid, the new filter BIO is freed and the functionreturns a NULL result indicating a failure. However, in this case, the BIO chainis not properly cleaned up and the BIO passed by the caller still retainsinternal pointers to the previously freed filter BIO. If the caller then goes onto call BIO_pop() on the BIO then a use-after-free will occur. This will mostlikely result in a crash.This scenario occurs directly in the internal function B64_write_ASN1() whichmay cause BIO_new_NDEF() to be called and will subsequently call BIO_pop() onthe BIO. This internal function is in turn called by the public API functionsPEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream, PEM_write_bio_PKCS7_stream,SMIME_write_ASN1, SMIME_write_CMS and SMIME_write_PKCS7.Other public API functions that may be impacted by this includei2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7, i2d_CMS_bio_stream andi2d_PKCS7_bio_stream.The OpenSSL cms and smime command line applications are similarly affected.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					],
					"details":"mysql security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2072"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2023-0215"
		},
		{
			"cve":"CVE-2023-38545",
			"notes":[
				{
					"text":"This flaw makes curl overflow a heap based buffer in the SOCKS5 proxyhandshake.When curl is asked to pass along the host name to the SOCKS5 proxy to allowthat to resolve the address instead of it getting done by curl itself, themaximum length that host name can be is 255 bytes.If the host name is detected to be longer, curl switches to local nameresolving and instead passes on the resolved address only. Due to this bug,the local variable that means  let the host resolve the name  could get thewrong value during a slow SOCKS5 handshake, and contrary to the intention,copy the too long host name to the target buffer instead of copying just theresolved address there.The target buffer being a heap based buffer, and the host name coming from theURL that curl has been told to operate with.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					],
					"details":"mysql security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2072"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2023-38545"
		},
		{
			"cve":"CVE-2024-21137",
			"notes":[
				{
					"text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.35 and prior and  8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					],
					"details":"mysql security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2072"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":4.9,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2024-21137"
		},
		{
			"cve":"CVE-2024-21159",
			"notes":[
				{
					"text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
					"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
					"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					],
					"details":"mysql security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-2072"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":4.9,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.aarch64",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.src",
						"openEuler-22.03-LTS-SP1:mysql-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-common-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-config-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debuginfo-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-debugsource-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-devel-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-errmsg-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-help-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-libs-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-server-8.0.38-1.oe2203sp1.x86_64",
						"openEuler-22.03-LTS-SP1:mysql-test-8.0.38-1.oe2203sp1.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2024-21159"
		}
	]
}