CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-11 05:15

Updated : 2024-04-11 12:47


NVD link : CVE-2024-21508

Mitre link : CVE-2024-21508

CVE.ORG link : CVE-2024-21508


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')