mysql
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mysqlpage 1 of 1
- CVE-2015-9244CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.0-alpha82018-05-29
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
- CVE-2019-14939MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.18.02019-08-12
vulnerable: 2.17.1
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.
Check whether mysql is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mysql CVEs against the assets you own.
Start Free Scan →