{"id":"GHSA-qxvw-fvwx-5cp7","summary":"org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials","details":"### Summary\n\nWhen PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.\n\n### Details\n\nThe mysql_clear_password plugin is gated behind a secure connection: the driver refuses to transmit the password in cleartext over plain TCP. The sibling PAM plugin handler (SendPamAuthPacketFactory, server-side plugin name dialog) did not override that gate and inherited the default value false, so it was not subject to the same secure-transport requirement.\n\nAs a result, a hostile or man-in-the-middle server can issue an Authentication Switch Request for the dialog plugin over plain TCP, and the driver responds with the user's password in cleartext. With the default configuration (sslMode=DISABLE, restrictedAuth=null) this is reachable with no non-default options.\n\n### Am I affected?\n\nYou are affected if all of the following hold:\n\n\n* You use mariadb Connector/J at a version below the patched release(s).\n* Connections can occur over an insecure transport — i.e. plain TCP (sslMode=DISABLE), or a TLS mode that establishes server identity only via self-signed-certificate fingerprint validation.\n* An attacker can occupy an on-path (MITM) position, or otherwise cause the client to connect to a server they control, and present an Authentication Switch Request for the dialog plugin.\n\nConnections over properly verified TLS or a local Unix socket are not exposed to this vector.\n\n### Impact\n\nDisclosure of the authenticating account's password in cleartext to an on-path or hostile server. The captured credentials can then be reused to authenticate to the database.\n\n### Patches\n\nFixed in 2.7.14, 3.3.5, 3.4.3, and 3.5.9. Upgrade to the patched release on your branch (3.5.x → 3.5.9, 3.4.x → 3.4.3, 3.0/3.1/3.2/3.3.x → 3.3.5, 2.x → 2.7.14). PAM (dialog) is now treated exactly like mysql_clear_password: it may only run over a secure transport. SendPamAuthPacketFactory overrides the secure-required flag to true, and the authentication dispatcher permits a secure-required plugin only when the connection is TLS or a local Unix socket. The pre-existing check that blocks non-MITM-proof plugins when server identity relies solely on self-signed-certificate fingerprint validation continues to apply. Net effect: PAM is allowed over TLS or a Unix socket, and rejected over plain TCP or fingerprint-only connections.\n\n### Workarounds\n\nIf you cannot upgrade immediately:\n\n* Connect over verified TLS (set sslMode=verify-full) so a man-in-the-middle cannot impersonate the server, or use a local Unix socket.\n* Restrict the permitted authentication plugins via restrictedAuth so dialog cannot be negotiated over an insecure transport.\n\n\n### Credit\n\nReported by Yalguun Tumenkhuu ([@fg0x0](https://github.com/fg0x0/)).","aliases":["CVE-2026-55857"],"modified":"2026-08-28T23:10:58.920268Z","published":"2026-08-28T22:45:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-28T22:45:01Z","nvd_published_at":null,"cwe_ids":["CWE-319","CWE-522"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/security/advisories/GHSA-qxvw-fvwx-5cp7"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/commit/a8599ab1cbe4b8818ea945bf56a4e012c302b388"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/commit/f4a727c764d1cf48fd0c3d5e301dfa92503e0a58"},{"type":"PACKAGE","url":"https://github.com/mariadb-corporation/mariadb-connector-j"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/releases/tag/3.4.3"},{"type":"WEB","url":"https://github.com/mariadb-corporation/mariadb-connector-j/releases/tag/3.5.9"},{"type":"WEB","url":"https://jira.mariadb.org/browse/CONJ-1320"}],"affected":[{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.14"}]}],"versions":["1.1.10","1.1.7","1.1.8","1.1.9","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.0-beta-1","1.3.0-beta-2","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.4.0","1.4.0-beta-1","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.5.0-RC1","1.5.1-RC","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.8.0","2.0.0-RC","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.6.2","2.7.0","2.7.1","2.7.10","2.7.11","2.7.12","2.7.13","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.7.8","2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxvw-fvwx-5cp7/GHSA-qxvw-fvwx-5cp7.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.3.5"}]}],"versions":["3.0.1-beta","3.0.10","3.0.11","3.0.2-rc","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxvw-fvwx-5cp7/GHSA-qxvw-fvwx-5cp7.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.4.0"},{"fixed":"3.4.3"}]}],"versions":["3.4.0","3.4.1","3.4.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxvw-fvwx-5cp7/GHSA-qxvw-fvwx-5cp7.json"}},{"package":{"name":"org.mariadb.jdbc:mariadb-java-client","ecosystem":"Maven","purl":"pkg:maven/org.mariadb.jdbc/mariadb-java-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"3.5.9"}]}],"versions":["3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-qxvw-fvwx-5cp7/GHSA-qxvw-fvwx-5cp7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}