CVE-2024-21512
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2epss 3.1%
exploitation probability
3.1%top 13% of all CVEs
observed exploitation
nono source reports it
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L/E:P
References
https://gist.github.com/domdomi3/e9f0f9b9b1ed6bfbbc0bea87c5ca1e4ahttps://github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bchttps://github.com/sidorares/node-mysql2/pull/2702https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-7176010https://security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580