Vulnerabilities > CVE-2022-31026 - Use of Uninitialized Resource vulnerability in Trilogy Project Trilogy 0.0.1/2.0.0/2.1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
trilogy-project
CWE-908

Summary

Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. Users of the trilogy gem should upgrade to version 2.1.1 This issue can be avoided by only connecting to trusted servers.

Vulnerable Configurations

Part Description Count
Application
Trilogy_Project
3

Common Weakness Enumeration (CWE)