Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2024-04-23T05:00:00.602Z
Updated: 2024-08-01T22:20:40.911Z
Reserved: 2023-12-22T12:33:20.120Z
Link: CVE-2024-21511
Vulnrichment
Updated: 2024-08-01T22:20:40.911Z
NVD
Status : Awaiting Analysis
Published: 2024-04-23T05:15:48.963
Modified: 2024-04-23T12:52:09.397
Link: CVE-2024-21511
Redhat