Impact
The flaw appears in MariaDB Connector/Node.js when the permitSetMultiParamEntries option is enabled. Object keys are inserted into a SQL SET clause without escaping identifiers, allowing an attacker to close a backtick‑quoted identifier and inject arbitrary SQL. This could result in modification of unintended columns or execution of additional statements with the database user’s permissions, mapped to CWE-89 (SQL Injection).
Affected Systems
MariaDB Corporation’s MariaDB Connector/Node.js for Node.js applications is affected. Vulnerable releases include 3.2.0 through 3.2.4. The issue was addressed in releases 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. EPSS data is unavailable, and the flaw is not listed in CISA KEV. The likely attack vector involves a remote application that enables permitSetMultiParamEntries and sends maliciously crafted object keys to the connector. The default setting disables the option, so risk is mitigated when configurations remain at default, but any intentional enabling presents a significant risk. Given the high CVSS, the potential for data tampering or unauthorized query execution warrants prompt action.
OpenCVE Enrichment
Github GHSA