MEDIUM
GHSA-5f7m-mmpc-qhh4
mysql Node.JS Module Vulnerable to Remote Memory Exposure
Quick fix
GHSA-5f7m-mmpc-qhh4 — mysql: upgrade to the fixed version with the command below.
npm install mysql@2.14.0Details
Versions of `mysql` before 2.14.0 are vulnerable to remove memory exposure.
Affected versions of `mysql` package allocate and send an uninitialized memory over the network when a number is provided as a password.
Only `mysql` running on Node.js versions below 6.0.0 are affected due to a throw added in newer node.js versions.
Proof of Concept:
``` require('mysql').createConnection({ host: 'localhost', user: 'user', password : USERPROVIDEDINPUT, // number database : 'my_db' }).connect(); ```
## Recommendation
Update to version 2.14.0 or later.
Are you affected?
Enter the version of the package you're using.