org.webjars.npm:mysql2@1.5.3 vulnerabilities

  • latest version

    1.5.3

  • first published

    6 years ago

  • latest version published

    6 years ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the org.webjars.npm:mysql2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

org.webjars.npm:mysql2 is a mostly API compatible with mysqljs and supports majority of features.

Affected versions of this package are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

How to fix Prototype Pollution?

A fix was pushed into the master branch but not yet published.

[0,)
  • M
Man in The Middle (MiTM)

org.webjars.npm:mysql2 is a mostly API compatible with mysqljs and supports majority of features.

Affected versions of this package are vulnerable to Man in The Middle (MiTM). The package does not verify remote certificates and reject unauthorized SSL connections.

How to fix Man in The Middle (MiTM)?

There is no fixed version for org.webjars.npm:mysql2.

[0,)