/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-21507

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-21507

CGA ID

CGA-hgjg-3j78-ggcp

Severity

6.5

Medium

CVSS V3

Description

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images