CVE-2024-21512: mysql2 vulnerable to Prototype Pollution
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
References
- gist.github.com/domdomi3/e9f0f9b9b1ed6bfbbc0bea87c5ca1e4a
- github.com/advisories/GHSA-pmh2-wpjm-fj45
- github.com/sidorares/node-mysql2
- github.com/sidorares/node-mysql2/commit/efe3db527a2c94a63c2d14045baba8dfefe922bc
- github.com/sidorares/node-mysql2/pull/2702
- nvd.nist.gov/vuln/detail/CVE-2024-21512
- security.snyk.io/vuln/SNYK-JS-MYSQL2-6861580
Detect and mitigate CVE-2024-21512 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →