Vulnerability

CVE-2024-21508
CVSS Score 10.0 critical

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWE

CWE-94

[CVE-2024-21508] CWE-94: Improper Control of Generation of Code ('Code Injection')

Description

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

See mysql2 package information