MariaDB MCP Unauthorized Access Vulnerability in SSE Service
Vulnerability
A vulnerability allowing unauthorized access to sensitive information has been identified in MariaDB MCP version 0.1.0. This issue arises because the Server-Sent Events (SSE) service does not validate user authentication, leaving it open to exploitation.
Impact
Exploitation of this vulnerability allows attackers to access sensitive database information without proper authentication.
Reproduction
The vulnerability can be reproduced by running a local server with the SSE transport option enabled. Once the server is active, access can be gained to the SSE endpoint, where sensitive database information can be retrieved.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
