CVE-2024-21509
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P
Affected products
n/a · mysql2References
https://blog.slonser.info/posts/mysql2-attacker-configuration/https://github.com/sidorares/node-mysql2/blob/fd3d117da82cc5c5fa5a3701d7b33ca77691bc61/lib/parsers/text_parser.js%23L134https://github.com/sidorares/node-mysql2/commit/4a964a3910a4b8de008696c554ab1b492e9b4691https://github.com/sidorares/node-mysql2/pull/2574https://github.com/sidorares/node-mysql2/releases/tag/v3.9.4https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6591084