VulnerabilityAnalyzed
CVE-2024-21509
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.
MEDIUM 6.5EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- sidorares/mysql2
- Source
- report@snyk.io
References
- https://blog.slonser.info/posts/mysql2-attacker-configuration/Exploit, Permissions Required
- https://github.com/sidorares/node-mysql2/blob/fd3d117da82cc5c5fa5a3701d7b33ca77691bc61/lib/parsers/text_parser.js%23L134Broken Link
- https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691Patch
- https://github.com/sidorares/node-mysql2/pull/2574Exploit, Issue Tracking
- https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4Release Notes
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591084Exploit, Third Party Advisory
- https://blog.slonser.info/posts/mysql2-attacker-configuration/Exploit, Permissions Required
- https://github.com/sidorares/node-mysql2/blob/fd3d117da82cc5c5fa5a3701d7b33ca77691bc61/lib/parsers/text_parser.js%23L134Broken Link
- https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691Patch
- https://github.com/sidorares/node-mysql2/pull/2574Exploit, Issue Tracking
- https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4Release Notes
- https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591084Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.