mysql-connector-python is vulnerable to Remote Code Execution (RCE)
35
Low Risk
Affected versions of this package are vulnerable to remote code execution (RCE) due to improper validation and handling of configuration files. Specifically, an attacker can craft a malicious configuration file containing arbitrary code or commands that the application processes unsafely. When the application reads and executes the contents of this file, the embedded code runs with the same privileges as the application, allowing the attacker to execute arbitrary commands on the host system.
You are affected if you are using a version of this package = 9.1.0.
mysql-connector-python is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 9.1.0.
Upgrade the mysql-connector-python library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant