Debian Node-Mysql vulnerabilities
2 known vulnerabilities affecting debian/node-mysql.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2015-9244P3LOWCVSS 9.8fixed in node-mysql 2.0.0~alpha8-1 (bookworm)2015
CVE-2015-9244 [CRITICAL] CVE-2015-9244: node-mysql - Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped w...
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Scope: local
bookworm: resolved (fixed in 2.0.0~alpha8-1)
bullseye: resolved (fixed in 2.0.0~alpha8-1)
forky: resolved (fixed in 2.0.0~alpha8-1)
sid: resolved (fixed in 2.0.0~alpha8-1)
trixie: resolved (fixed in 2.0.0~alpha8-1)
debian
CVE-2019-14939P4MEDIUMCVSS 5.5fixed in node-mysql 2.18.0-1 (bookworm)2019
CVE-2019-14939 [MEDIUM] CVE-2019-14939: node-mysql - An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. Th...
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.
Scope: local
bookworm: resolved (fixed in 2.18.0-1)
bullseye: resolved (fixed in 2.18.0-1)
forky: resolved (fixed in 2.18.0-1)
sid: resolved (fixed in 2.18.0-1)
trixie: resolved (fixed in 2.18.0-1)
debian