CVE-2024-21507
10.04.2024, 05:15
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mysqljs | mysql2 | 𝑥 < 3.9.3 |
| sidorares | mysql2 | 𝑥 < 3.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References