THREAT OPS › Threat News › [GHSA] GHSA-3f6p-5ww8-9rcr (high) — MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
[GHSA] GHSA-3f6p-5ww8-9rcr (high) — MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
GHSA-3f6p-5ww8-9rcr Severity: high CVE: None
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
## Summary
A rogue MySQL server (or MITM) can force mysql2 to send credentials in **plaintext** by requesting an auth switch to `mysql_clear_password`. The driver complies without verifying that TLS is active.
## Details
`mysql_clear_password` is registered as a defau
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://github.com/advisories/GHSA-3f6p-5ww8-9rcr