/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-21507

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-21507

Severity

5.3

Medium

CVSS V3

Description

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing