CVE-2024-21511
EUVD-2024-109223.04.2024, 05:15
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mysql2 | mysql2 | 𝑥 < 3.9.7 |
𝑥
= Vulnerable software versions
References