CVE-2024-21511
23.04.2024, 05:15
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Vendor | Product | Version |
---|---|---|
mysql2 | mysql2 | 𝑥 < 3.9.7 |
𝑥
= Vulnerable software versions
References