Описание
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.
Ссылки
- ExploitPermissions Required
- Patch
- ExploitIssue Tracking
- ExploitThird Party Advisory
- ExploitPermissions Required
- Patch
- ExploitIssue Tracking
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.9.3 (исключая)
cpe:2.3:a:sidorares:mysql2:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00322
Низкий
6.5 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-20
CWE-20
Связанные уязвимости
CVSS3: 6.5
redhat
почти 2 года назад
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.
EPSS
Процентиль: 55%
0.00322
Низкий
6.5 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-20
CWE-20