Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21511

Опубликовано: 23 апр. 2024
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

A flaw was found in the MySQL2 npm package. Affected versions of this package are vulnerable to arbitrary code injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh-hub-containerNot affected
Red Hat Developer Hubrhdh-operator-containerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2276801mysql2: Arbitrary Code Injection due to improper sanitization of the timezone parameter

EPSS

Процентиль: 61%
0.01025
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

CVSS3: 9.8
github
больше 2 лет назад

MySQL2 for Node Arbitrary Code Injection

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость функции readCodeFor библиотеки для работы с базами данных mysql2, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 61%
0.01025
Низкий

9.8 Critical

CVSS3