{
  "entrypoint_kind": "tcp_peer",
  "entrypoint_detail": "A malicious MariaDB Galera joiner connected to the donor on wsrep TCP port 4567 and sent a mariabackup SST request whose certificate CN became remote_auth.",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "MariaDB 11.8.6",
    "Galera 4",
    "wsrep_sst_mariabackup",
    "OpenSSL",
    "socat"
  ],
  "target_identity": {
    "repository_url": "https://github.com/MariaDB/server.git",
    "commit_sha": "46a8eb42a520193686d9a16d4cea4b3e002917e4",
    "target_digest": "b68d5e7543ed658ab3761d49e6bc068650eefe4a388a50cd45bcab898fe44d09",
    "runtime_digest": "78a5047d3ba33975f183f183c2464cc7f1eab13ec8667e57cc9a5821d6da7577",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "logs/reproduction_steps.log",
    "logs/source_identity.log",
    "logs/vulnerable_donor.log",
    "logs/vulnerable_joiner.log",
    "logs/fixed_donor.log",
    "logs/fixed_joiner.log",
    "logs/product_linkage.log",
    "repro/donor_command_marker.txt",
    "repro/fixed_negative_control.json"
  ],
  "artifact_sha256": {
    "logs/reproduction_steps.log": "91bacbb97d5f1cb6a751c1b09c9ad79c7326b387f312c72d52ff3f7a62565f8a",
    "logs/source_identity.log": "f8e5369c3e7d8d6994bc96d54316f525d96c771b7bc619c54b406bbc41928f1e",
    "logs/vulnerable_donor.log": "ebaaf4f1875a1b00accf4512188c3715609af1805c3d5a0f2cdafb230c9e310f",
    "logs/vulnerable_joiner.log": "b30d274b5faa47f422851dbe9a367489a8270745f5b1fc3f178d57db1de48025",
    "logs/fixed_donor.log": "571a1d284119832772b41e5172fa000dcca5c10dd3102028abaabfd16fdaeb26",
    "logs/fixed_joiner.log": "b8801aea5da54717e0bfb43c23e9287849ce1892f44f00e84f62f74c538d24bb",
    "logs/product_linkage.log": "b3b92dc8978d8e3145451f157bc418cae0e9cb7fe1911e141a398ae4feceba2b",
    "repro/donor_command_marker.txt": "712777b2f1d2dc0868a05aee80501e0ee2287888c62115cb8f068659da10e7bb",
    "repro/fixed_negative_control.json": "538a52f0299e80046bf7dc42f656976c68fc3de37e91850316e5ec4b55f11dae"
  },
  "notes": "Vulnerable donor executed id as uid=999(mysql). Fixed commit 581562f94a rejected the same remote_auth on the same TCP SST path without creating a marker."
}
