GHSA-73pr-g6jj-5hc9
Dashboard / Vulnerabilities / GHSA-73pr-g6jj-5hc9
Summary: Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
Details: A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server).
References: https://nvd.nist.gov/vuln/detail/CVE-2021-3779, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-mysql/CVE-2021-3779.yml, https://www.rapid7.com/blog/post/2022/06/28/cve-2021-3779-ruby-mysql-gem-client-file-read-fixed, http://github.com/tmtm/ruby-mysql
Affected packages
Package
Name: ruby-mysql
Purl: pkg:gem/ruby-mysql
Affected ranges
Type: ECOSYSTEM
Events:
