# MySQL vulnerabilities CVE-2022-1292

**URL:** <https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393>\
**Category:** Percona Distribution for MySQL\
**Tags:** mysql, percona, new-release\
**Created:** [September 9, 2022, 9:53pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393 "2022-09-09T21:53:42Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vincentp](https://avatars.discourse-cdn.com/v4/letter/v/f19dbf/32.png) [@vincentp](https://forums.percona.com/u/vincentp)\
**Post date:** [September 9, 2022, 9:53pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/1 "2022-09-09T21:53:43Z")

</div>

Oracle MySQL CVE-2022-1292 is high and only resolved through 8.0.30  
When can this version be expected?  
Will commercial scanners detect this vulnerability?

> **[Oracle Critical Patch Update Advisory - July 2022](https://www.oracle.com/security-alerts/cpujul2022.html#AppendixMSQL)**
>
> Oracle Critical Patch Update Advisory - July 2022

---

<div class="post-metadata">

**Author:** ![DebbieHunt](https://avatars.discourse-cdn.com/v4/letter/d/d26b3c/32.png) [@DebbieHunt](https://forums.percona.com/u/DebbieHunt)\
**Post date:** [September 12, 2022, 2:47pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/2 "2022-09-12T14:47:13Z")

</div>

I haven’t seen a response here. This is a high risk patch that needs to be distributed ASAP. Please provide status.

---

<div class="post-metadata">

**Author:** ![daniil.bazhenov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniil.bazhenov/32/62_2.png) [@daniil.bazhenov](https://forums.percona.com/u/daniil.bazhenov)\
**Post date:** [September 13, 2022, 5:12pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/3 "2022-09-13T17:12:44Z")

</div>

Hi,

It is fixed in Oracle MySQL 8.0.30 and will thus be fixed with Percona Server for MySQL 8.0.30 when it is released, which will be in the coming weeks.

---

<div class="post-metadata">

**Author:** ![DebbieHunt](https://avatars.discourse-cdn.com/v4/letter/d/d26b3c/32.png) [@DebbieHunt](https://forums.percona.com/u/DebbieHunt)\
**Post date:** [September 13, 2022, 5:19pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/4 "2022-09-13T17:19:15Z")

</div>

I appreciate that, but I do need a target date that I can report back to our security team. Our organization policy is that any **HIGH** findings must be corrected in 90 days or less.

---

<div class="post-metadata">

**Author:** ![daniil.bazhenov](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniil.bazhenov/32/62_2.png) [@daniil.bazhenov](https://forums.percona.com/u/daniil.bazhenov)\
**Post date:** [September 13, 2022, 5:43pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/5 "2022-09-13T17:43:18Z")

</div>

I understand, probably someone from the development team will see the question and give a more accurate answer on the dates.

---

<div class="post-metadata">

**Author:** ![DebbieHunt](https://avatars.discourse-cdn.com/v4/letter/d/d26b3c/32.png) [@DebbieHunt](https://forums.percona.com/u/DebbieHunt)\
**Post date:** [September 27, 2022, 6:15pm UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/6 "2022-09-27T18:15:22Z")

</div>

Still no response from @DevTeam?

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Patlan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/evgeniy_patlan/32/41_2.png) [@Evgeniy\_Patlan](https://forums.percona.com/u/Evgeniy_Patlan)\
**Post date:** [October 18, 2022, 11:06am UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/7 "2022-10-18T11:06:21Z")

</div>

Hey @vincentp  
The issue reported by oracle mostly connected to openssl version. So updating openssl to the latest version should solve it

---

<div class="post-metadata">

**Author:** ![DebbieHunt](https://avatars.discourse-cdn.com/v4/letter/d/d26b3c/32.png) [@DebbieHunt](https://forums.percona.com/u/DebbieHunt)\
**Post date:** [October 20, 2022, 3:44am UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/8 "2022-10-20T03:44:50Z")

</div>

I see that 8.0.30 is still not released. Is there an estimate yet?

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Patlan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/evgeniy_patlan/32/41_2.png) [@Evgeniy\_Patlan](https://forums.percona.com/u/Evgeniy_Patlan)\
**Post date:** [October 21, 2022, 8:39am UTC](https://forums.percona.com/t/mysql-vulnerabilities-cve-2022-1292/17393/9 "2022-10-21T08:39:29Z")

</div>

@DebbieHunt the work is in progress but we don’t have the exact release date yet
