CVE-2024-21512
mysql2 vulnerable to Prototype Pollution
8.2
HIGH
CVSS 3.1
EPSS 3.1%
Description
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
How to fix CVE-2024-21512
To remediate CVE-2024-21512, upgrade the affected package to a fixed version below.
- npm/mysql2—upgrade to 3.9.8 or later
Is CVE-2024-21512 being exploited?
Low — EPSS is 3.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.9.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |