CVE-2024-21511
EUVD-2024-109223.04.2024, 05:15
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mysql2 | mysql2 | 𝑥 < 3.9.7 | ADP |
References