MEDIUM6.5
GHSA-mqr2-w7wj-jjgr
mysql2 cache poisoning vulnerability
Quick fix
GHSA-mqr2-w7wj-jjgr — mysql2: upgrade to the fixed version with the command below.
npm install mysql2@3.9.3Details
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the `keyFromFields` function, resulting in cache poisoning. An attacker can inject a colon `:` character within a value of the attacker-crafted key.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21507[ADVISORY]
- https://github.com/sidorares/node-mysql2/pull/2424[WEB]
- https://github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818[WEB]
- https://blog.slonser.info/posts/mysql2-attacker-configuration[WEB]
- https://github.com/sidorares/node-mysql2[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591300[WEB]