CVE-2019-14939Sensitive Information Exposure in Oracle Mysql

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 81.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 24

Description

An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

npmoracle/mysql2.17.12.18.0

🔴Vulnerability Details

4
OSV
MySQL for Node.js Unsafe Options2022-05-24
GHSA
MySQL for Node.js Unsafe Options2022-05-24
CVEList
CVE-2019-14939: An issue was discovered in the mysql (aka mysqljs) module 22019-08-12
OSV
CVE-2019-14939: An issue was discovered in the mysql (aka mysqljs) module 22019-08-12

📋Vendor Advisories

1
Debian
CVE-2019-14939: node-mysql - An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. Th...2019

💬Community

3
Bugzilla
CVE-2019-14939 nodejs-mysql: LOAD DATA LOCAL INFILE option is open by default2019-08-19
Bugzilla
CVE-2019-14939 nodejs-mysql: LOAD DATA LOCAL INFILE option is open by default [epel-all]2019-08-19
Bugzilla
CVE-2019-14939 nodejs-mysql: LOAD DATA LOCAL INFILE option is open by default [fedora-all]2019-08-19
CVE-2019-14939 — Sensitive Information Exposure | cvebase