org.webjars.npm:mysql2@1.5.3 vulnerabilities

  • latest version

    1.5.3

  • first published

    7 years ago

  • latest version published

    7 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.webjars.npm:mysql2 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Prototype Pollution

    org.webjars.npm:mysql2 is a mostly API compatible with mysqljs and supports majority of features.

    Affected versions of this package are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.

    How to fix Prototype Pollution?

    A fix was pushed into the master branch but not yet published.

    [0,)
    • M
    Man in The Middle (MiTM)

    org.webjars.npm:mysql2 is a mostly API compatible with mysqljs and supports majority of features.

    Affected versions of this package are vulnerable to Man in The Middle (MiTM). The package does not verify remote certificates and reject unauthorized SSL connections.

    How to fix Man in The Middle (MiTM)?

    There is no fixed version for org.webjars.npm:mysql2.

    [0,)