HIGH8.2
GHSA-pmh2-wpjm-fj45
mysql2 vulnerable to Prototype Pollution
Quick fix
GHSA-pmh2-wpjm-fj45 — mysql2: upgrade to the fixed version with the command below.
npm install mysql2@3.9.8Details
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21512[ADVISORY]
- https://github.com/sidorares/node-mysql2/pull/2702[WEB]
- https://github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bc[WEB]
- https://gist.github.com/domdomi3/e9f0f9b9b1ed6bfbbc0bea87c5ca1e4a[WEB]
- https://github.com/sidorares/node-mysql2[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-7176010[WEB]
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580[WEB]