ruby-mysql
This is MySQL connector. pure Ruby version
Activity
- Latest release
- 8mo ago
- Total releases
- 24
- Cadence
- ~6 months
- Last 12 months
- 1
Details
- License
- MIT
- First release
- Jul 28, 2009
| Version | Released | |
|---|---|---|
4.2.1
patch
|
4.2.1
patch
|
|
4.2.0
minor
|
4.2.0
minor
|
|
4.1.0
minor
|
4.1.0
minor
|
|
4.0.0
major
|
4.0.0
major
Dependencies (3)
|
|
3.0.1
patch
|
3.0.1
patch
|
|
3.0.0
major
|
3.0.0
major
|
|
2.11.1
patch
|
2.11.1
patch
|
|
2.11.0
minor
|
2.11.0
minor
|
|
2.10.0
minor
|
2.10.0
minor
|
|
2.9.14
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.14
patch
|
|
2.9.13
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.13
patch
|
|
2.9.12
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.12
patch
|
|
2.9.11
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.11
patch
|
|
2.9.10
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.10
patch
|
|
2.9.9
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.9
patch
|
|
2.9.8
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.8
patch
|
|
2.9.7
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.7
patch
|
|
2.9.6
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.6
patch
|
|
2.9.5
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.5
patch
|
|
2.9.4
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.4
patch
|
|
2.9.3
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.3
patch
|
|
2.9.2
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.2
patch
|
|
2.9.1
patch
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.1
patch
|
|
2.9.0
initial
1 CVE
CVE-2021-3779
GHSA-73pr-g6jj-5hc9
Jun 29, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
A malicious actor can read arbitrary files from a client that uses ruby-mysql to communicate to a rogue MySQL server and issue database queries. In these cases, the server has the option to create a database reply using the LOAD DATA LOCAL statement, which instructs the client to provide additional data from a local file readable by the client (and not a "local" file on the server). Affected versions
2.9.0
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
+ 3 more Show less
2.9.7
2.9.8
2.9.9
Fixed in
2.10.0
References Updated Feb 21, 2024 · Source: OSV.dev |
2.9.0
initial
|