Critical severity9.8NVD Advisory· Published Nov 4, 2022· Updated Jun 17, 2026
CVE-2022-3023
CVE-2022-3023
Description
Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/pingcap/tidbGo | <= 6.1.2 | — |
github.com/pingcap/tidbGo | >= 6.2.0, <= 6.4.0-alpha1 | — |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/peerdb-flowpkg:apk/chainguard/peerdb-flow-compatpkg:apk/chainguard/peerdb-flow-fipspkg:golang/github.com/pingcap/tidb
< 0+ 3 more
- (no CPE)range: < 0
- (no CPE)range: < 0.35.0-r0
- (no CPE)range: < 0
- (no CPE)range: <= 6.1.2
- pingcap/pingcap/tidbv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/pingcap/tidb/commit/d0376379d615cc8f263a0b17c031ce403c8dcbfbnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-7fxj-fr3v-r9gjghsaADVISORY
- huntr.dev/bounties/120f1346-e958-49d0-b66c-0f889a469540nvdPermissions RequiredThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-3023ghsaADVISORY
- advisory.dw1.io/45ghsaWEB
News mentions
0No linked articles in our index yet.