Intel

AIKIDO-2024-10037

mysql2 is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-21511 Published Apr 22, 2024

90

Critical Risk

This Affects:

JSmysql2
2.0.0 - 3.9.6
Fixed in 3.9.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the readCodeFor function (lib/parsers/text_parser.js and lib/parsers/binary_parser.js) due to improper validation of the 'timezone' value.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mysql2 is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 3.9.6.

How to fix this

Upgrade the mysql2 library to the patch version.