Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmh2-wpjm-fj45

Опубликовано: 30 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

mysql2 vulnerable to Prototype Pollution

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

Пакеты

Наименование

mysql2

npm
Затронутые версииВерсия исправления

< 3.9.8

3.9.8

EPSS

Процентиль: 87%
0.03114
Низкий

8.2 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 8.2
redhat
больше 2 лет назад

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

CVSS3: 8.2
nvd
больше 2 лет назад

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

CVSS3: 8.2
fstec
больше 2 лет назад

Уязвимость конфигурации nestTables библиотеки для работы с базами данных mysql2, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»

EPSS

Процентиль: 87%
0.03114
Низкий

8.2 High

CVSS3

Дефекты

CWE-1321