MEDIUM 6.5 npm
mysql2 cache poisoning vulnerability
GHSA-mqr2-w7wj-jjgr · CVE-2024-21507
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon : character within a value of the attacker-crafted key.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-21507
- WEB https://github.com/sidorares/node-mysql2/pull/2424
- WEB https://github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818
- WEB https://blog.slonser.info/posts/mysql2-attacker-configuration
- PACKAGE https://github.com/sidorares/node-mysql2
- WEB https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591300
Ready to move
Start Securing
Free, no credit card | First findings in minutes