CVE-2022-31026
Last modified
CVE-2022-31026 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack memory. Users of the trilogy gem should upgrade to version 2.1.1 This issue can be avoided by only connecting to trusted servers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trilogy Project | Trilogy | < 2.1.1 |
References
- https://github.com/github/trilogy/commit/6bed62789eaf119902b0fe247d2a91d56c31a962Patch, Third Party Advisory
- https://github.com/github/trilogy/security/advisories/GHSA-5g4r-2qhx-vqfmThird Party Advisory
- https://github.com/github/trilogy/commit/6bed62789eaf119902b0fe247d2a91d56c31a962Patch, Third Party Advisory
- https://github.com/github/trilogy/security/advisories/GHSA-5g4r-2qhx-vqfmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31026?
How severe is CVE-2022-31026?
How do I fix CVE-2022-31026?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31020Indy Node is the server portion of a distributed ledger purp…8.8
- CVE-2022-31021Ursa is a cryptographic library for use with blockchains. A …5.3
- CVE-2022-31022Bleve is a text indexing library for go. Bleve includes HTTP…5.5
- CVE-2022-31023Play Framework is a web framework for Java and Scala. Verion…7.5
- CVE-2022-31024richdocuments is the repository for NextCloud Collabra, the …6.5
- CVE-2022-31025Discourse is an open source platform for community discussio…5.3
- CVE-2022-31027OAuthenticator is an OAuth token library for the JupyerHub l…6.5
- CVE-2022-31028MinIO is a multi-cloud object storage solution. Starting wit…7.5
- CVE-2022-31029AdminLTE is a Pi-hole Dashboard for stats and configuration.…4.8
- CVE-2022-3103off-by-one in io_uring module.7.8
- CVE-2022-31030containerd is an open source container runtime. A bug was fo…5.5
- CVE-2022-31031PJSIP is a free and open source multimedia communication lib…9.8
Are you affected by CVE-2022-31026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
