CRITICAL9.8
GHSA-fpw7-j2hg-69v5
mysql2 Remote Code Execution (RCE) via the readCodeFor function
Quick fix
GHSA-fpw7-j2hg-69v5 — mysql2: upgrade to the fixed version with the command below.
npm install mysql2@3.9.4Details
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the `readCodeFor` function due to improper validation of the `supportBigNumbers` and `bigNumberStrings` values.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21508[ADVISORY]
- https://github.com/sidorares/node-mysql2/pull/2572[WEB]
- https://github.com/sidorares/node-mysql2/commit/74abf9ef94d76114d9a09415e28b496522a94805[WEB]
- https://blog.slonser.info/posts/mysql2-attacker-configuration[WEB]
- https://github.com/sidorares/node-mysql2[PACKAGE]
- https://github.com/sidorares/node-mysql2/blob/1609b5393516d72a4ae47196837317fbe75e0c13/lib/parsers/text_parser.js%23L14C10-L14C21[WEB]
- https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4[WEB]
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591085[WEB]