VDB
Sign up
CRITICAL9.8

GHSA-4rch-2fh8-94vw

MySQL2 for Node Arbitrary Code Injection

Quick fix

GHSA-4rch-2fh8-94vw — mysql2: upgrade to the fixed version with the command below.

npm install mysql2@3.9.7

Details

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mysql2
Introduced in: 0Fixed in: 3.9.7
Fixnpm install mysql2@3.9.7

References