mysql Node.JS Module Vulnerable to Remote Memory Exposure
Moderate severity
GitHub Reviewed
Published
May 23, 2019
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Description
Reviewed
May 23, 2019
Published to the GitHub Advisory Database
May 23, 2019
Last updated
Jan 11, 2023
Versions of
mysql
before 2.14.0 are vulnerable to remove memory exposure.Affected versions of
mysql
package allocate and send an uninitialized memory over the network when a number is provided as a password.Only
mysql
running on Node.js versions below 6.0.0 are affected due to a throw added in newer node.js versions.Proof of Concept:
Recommendation
Update to version 2.14.0 or later.
References