Description
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
Remediation
References
Related Vulnerabilities
WordPress Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-29447)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.19)
SharePoint CVE-2024-43466 Vulnerability (CVE-2024-43466)
Moodle Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-21809)
WordPress Plugin Meow Gallery (+ Gallery Block) Security Bypass (4.1.9)