Medium severity6.5NVD Advisory· Published Apr 10, 2024· Updated Jun 17, 2026
CVE-2024-21507
CVE-2024-21507
Description
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mysql2npm | < 3.9.3 | 3.9.3 |
Affected products
7- mysql2/mysql2description
- osv-coords5 versionspkg:apk/chainguard/sqlpadpkg:apk/chainguard/sqlpad-compatpkg:apk/wolfi/sqlpadpkg:apk/wolfi/sqlpad-compatpkg:npm/mysql2
< 7.4.1-r4+ 4 more
- (no CPE)range: < 7.4.1-r4
- (no CPE)range: < 7.4.1-r4
- (no CPE)range: < 7.4.1-r4
- (no CPE)range: < 7.4.1-r4
- (no CPE)range: < 3.9.3
Patches
Vulnerability mechanics
References
7- github.com/sidorares/node-mysql2/commit/0d54b0ca6498c823098426038162ef10df02c818nvdPatchWEB
- blog.slonser.info/posts/mysql2-attacker-configuration/nvdExploitPermissions Required
- github.com/sidorares/node-mysql2/pull/2424nvdExploitIssue TrackingWEB
- security.snyk.io/vuln/SNYK-JS-MYSQL2-6591300nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mqr2-w7wj-jjgrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-21507ghsaADVISORY
- blog.slonser.info/posts/mysql2-attacker-configurationghsaWEB
News mentions
0No linked articles in our index yet.