This is a vulnerability in the authentication scheme used in the MySQL wire protocol, meaning attackers need to be able to connect to your MySQL database directly to exploit it. Attackers should never, ever be able to connect directly to your MySQL database directly . If you can connect to your MySQL instance directly from your Macbook in your living room, fix it right now .
With this logic, let's not secure any software that you cannot connect to it directly.
Thus began years of efforts on our part of security fixes, which I would not have started except that I had customers to support.