THREAT OPS › Threat News › [GHSA] GHSA-qxvw-fvwx-5cp7 (medium) — org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
[GHSA] GHSA-qxvw-fvwx-5cp7 (medium) — org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-qxvw-fvwx-5cp7 Severity: medium CVE: CVE-2026-55857
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
### Summary
When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger t
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55857cve
Original source: https://github.com/advisories/GHSA-qxvw-fvwx-5cp7