{"id":"CVE-2021-3779","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-3779","summary":"Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql","details":"A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a \"local\" file on the server).","published":"2022-06-29T00:00:27Z","modified":"2024-02-21T05:29:44.756734Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"ruby-mysql","fixedVersion":"2.10.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3779"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-mysql/CVE-2021-3779.yml"},{"type":"WEB","url":"https://www.rapid7.com/blog/post/2022/06/28/cve-2021-3779-ruby-mysql-gem-client-file-read-fixed"},{"type":"PACKAGE","url":"http://github.com/tmtm/ruby-mysql"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-21T05:29:44.756734Z"}}