VDB
Sign up
MEDIUM6.5

GHSA-mqr2-w7wj-jjgr

mysql2 cache poisoning vulnerability

Quick fix

GHSA-mqr2-w7wj-jjgr — mysql2: upgrade to the fixed version with the command below.

npm install mysql2@3.9.3

Details

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the `keyFromFields` function, resulting in cache poisoning. An attacker can inject a colon `:` character within a value of the attacker-crafted key.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mysql2
Introduced in: 0Fixed in: 3.9.3
Fixnpm install mysql2@3.9.3

References