CVE Vulnerabilities

CVE-2021-3779

Externally Controlled Reference to a Resource in Another Sphere

Published: Jun 28, 2022 | Modified: Jul 07, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without explicit authorization from the user. This issue was resolved in version 2.10.0 and later.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Ruby-mysql Ruby-mysql_project * 2.10.0 (excluding)
Ruby-mysql Ubuntu esm-apps/xenial *

References