VDB
Sign up
MEDIUM

GHSA-5f7m-mmpc-qhh4

mysql Node.JS Module Vulnerable to Remote Memory Exposure

Quick fix

GHSA-5f7m-mmpc-qhh4 — mysql: upgrade to the fixed version with the command below.

npm install mysql@2.14.0

Details

Versions of `mysql` before 2.14.0 are vulnerable to remove memory exposure.

Affected versions of `mysql` package allocate and send an uninitialized memory over the network when a number is provided as a password.

Only `mysql` running on Node.js versions below 6.0.0 are affected due to a throw added in newer node.js versions.

Proof of Concept:

``` require('mysql').createConnection({ host: 'localhost', user: 'user', password : USERPROVIDEDINPUT, // number database : 'my_db' }).connect(); ```

## Recommendation

Update to version 2.14.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mysql
Introduced in: 2.0.0-alpha8Fixed in: 2.14.0
Fixnpm install mysql@2.14.0

References