CVE-2022-29240 is a high-severity vulnerability affecting ScyllaDB's Scylla database, which is API-compatible with Apache Cassandra and Amazon DynamoDB. The flaw, categorized as CWE-908 (Use of Uninitialized Value), arises from Scylla's incorrect handling of user-provided uncompressed lengths during CQL frame decompression, leading to uninitialized memory being exposed. This can result in authentication bypass for unauthenticated attackers using LZ4 compression, or sensitive information disclosure and authorization bypass for authenticated users. The CVSS score is 8.1 (HIGH), indicating a network-based attack with high impact on confidentiality, integrity, and availability, though requiring high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6.7CPE matchmatch criteria | cpe:2.3:a:scylladb:scylla:*:*:*:*:open_source:*:*:* | ||
< 2020.1.14CPE matchmatch criteria | cpe:2.3:a:scylladb:scylla:*:*:*:*:enterprise:*:*:* | ||
>= 5.0.0, < 5.0.3CPE matchmatch criteria | cpe:2.3:a:scylladb:scylla:*:*:*:*:open_source:*:*:* | ||
>= 2021.1.0, < 2021.1.12CPE matchmatch criteria | cpe:2.3:a:scylladb:scylla:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.