Unauthorized SSL Connection due to lack of cert authentication Affecting mysql package, versions <2.3.0 >=2.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Unauthorized SSL Connection due to lack of cert authentication vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:mysql:20140514
  • published4 Jan 2017
  • disclosed13 May 2014
  • creditDouglas Wilson

Introduced: 13 May 2014

CVE NOT AVAILABLE CWE-285  (opens in a new tab)

How to fix?

Upgrade mysql to version 2.3.0 or higher.

Overview

mysql is a node.js driver for mysql. Affected versions of this package do not validate that the remote server has a trusted SSL certificate or not, making it easier for attackers to gain access to the MySQL Server.

CVSS Base Scores

version 3.1