CVE-2024-21509

MEDIUM

sidorares/mysql2 < 3.9.4 - Prototype Pollution via Insecure Results Object Creation

Title source: llm
STIX 2.1

Description

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

Scores

CVSS v3 6.5
EPSS 0.0096
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
npm/mysql2 0 - 3.9.4npm
sidorares/mysql2 < 3.9.4
Published Apr 10, 2024
Tracked Since Feb 18, 2026