CVE-2022-31011

HIGH

TiDB 5.3.0 - Improper Authentication Bypass

Title source: llm
STIX 2.1

Description

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the authentication process, resulting in privilege escalation or unauthorized access. Only users using TiDB 5.3.0 are affected by this vulnerability. TiDB version 5.3.1 contains a patch for this issue. Other mitigation strategies include turning off Security Enhanced Mode (SEM), disabling local login for non-root accounts, and ensuring that the same IP cannot be logged in as root and normal user at the same time.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/pingcap/tidb/security/advisories/GHSA-4whx-7p29-mq22
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/pingcap/tidb/releases/tag/v5.3.1

Scores

CVSS v3 7.8
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (2)
pingcap/tidb 5.3.0
pingcap/tidb 5.3.0 - 5.3.1Go
Published May 31, 2022
Tracked Since Feb 18, 2026