chore(deps): update dependency mysql2 to v3.22.0 [security] - #1573
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency mysql2 to v3.22.0 [security]#1573renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.2.0→3.22.0mysql2 cache poisoning vulnerability
CVE-2024-21507 / GHSA-mqr2-w7wj-jjgr
More information
Details
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the
keyFromFieldsfunction, resulting in cache poisoning. An attacker can inject a colon:character within a value of the attacker-crafted key.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 vulnerable to Prototype Poisoning
CVE-2024-21509 / GHSA-49j4-86m8-q2jw
More information
Details
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through
parserFnintext_parser.jsandbinary_parser.js.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 Remote Code Execution (RCE) via the readCodeFor function
CVE-2024-21508 / GHSA-fpw7-j2hg-69v5
More information
Details
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the
readCodeForfunction due to improper validation of thesupportBigNumbersandbigNumberStringsvalues.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
MySQL2 for Node Arbitrary Code Injection
CVE-2024-21511 / GHSA-4rch-2fh8-94vw
More information
Details
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
mysql2 vulnerable to Prototype Pollution
CVE-2024-21512 / GHSA-pmh2-wpjm-fj45
More information
Details
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
GHSA-3f6p-5ww8-9rcr
More information
Details
Summary
A rogue MySQL server (or MITM) can force mysql2 to send credentials in plaintext by requesting an auth switch to
mysql_clear_password. The driver complies without verifying that TLS is active.Details
mysql_clear_passwordis registered as a default standard plugin inlib/commands/auth_switch.js(line 21). When a server sends an AuthSwitchRequest (0xFE) requestingmysql_clear_password, the driver executes it without checking for TLS. The plugin (lib/auth_plugins/mysql_clear_password.js) returnsBuffer.from(password + '\0').Note:
caching_sha2_passwordplugin DOES check for SSL before sending cleartext (line 77). Butmysql_clear_passwordhas no such guard.Attack Scenario
caching_sha2_passwordin handshakemysql_clear_passwordPoC
Rogue MySQL server (Node.js, ~80 lines) that captures plaintext passwords from mysql2 clients. Tested against mysql2 3.20.0. Full PoC available on request.
Suggested Fix
Remove
mysql_clear_passwordfromstandardAuthPlugins, or add a guard requiring TLS/unix socket before allowing cleartext auth.Impact
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
sidorares/node-mysql2 (mysql2)
v3.22.0Compare Source
Features
Performance Improvements
v3.21.1Compare Source
Bug Fixes
v3.21.0Compare Source
Features
v3.20.0Compare Source
Features
Bug Fixes
PoolConnectionas subclass ofConnection(#4183) (97855a6)v3.19.1Compare Source
Bug Fixes
null-terminated string read to packet end (fixes a potential OOB read reported by Doruk Tan Ozturk (peaktwilight)) (#4161) (91c5229)URL-defined connection options (fixes a potential config injection vulnerability reported by Doruk Tan Ozturk (peaktwilight)) (#4162) (3123b4e)v3.19.0Compare Source
Features
Bug Fixes
v3.18.2Compare Source
Bug Fixes
supportBigNumbers,bigNumberStrings,dateStrings, andtimezoneoptions toQueryOptions(#4127) (b274e72)QueryValuesto callback-based methods (#4129) (2ad5f0b)ExecuteValues"nested" params (#4133) (3f94950)RawandUint8Arrayparams (#4132) (bde9aec)v3.18.1Compare Source
Bug Fixes
queryandexecutemethods (#4123) (3f4bbca)v3.18.0Compare Source
Features
Symbol.disposeandSymbol.asyncDisposesupport for Connections, Pools, and Pool Clusters (#4112) (1e612dc)v3.17.5Compare Source
Bug Fixes
@types/nodeas a peer dependency (#4108) (5f8ac97)v3.17.4Compare Source
Bug Fixes
v3.17.3Compare Source
Bug Fixes
PoolConnection.endcallback and promise resolution (#3937) (18ff2c6)v3.17.2Compare Source
Bug Fixes
v3.17.1Compare Source
Bug Fixes
ON DUPLICATE KEY UPDATEpreceded bySET(#4076) (4d2b930)v3.17.0Compare Source
Bug Fixes
v3.16.3Compare Source
Bug Fixes
v3.16.2Compare Source
Bug Fixes
ConnectionStatetype to Promise Connection interface (#4034) (2927949)v3.16.1Compare Source
Bug Fixes
v3.16.0Compare Source
Features
v3.15.3Compare Source
Bug Fixes
v3.15.2Compare Source
Bug Fixes
v3.15.1Compare Source
Bug Fixes
v3.15.0Compare Source
Features
v3.14.5Compare Source
Bug Fixes
v3.14.4Compare Source
Bug Fixes
v3.14.3Compare Source
Bug Fixes
v3.14.2Compare Source
Bug Fixes
v3.14.1Compare Source
Miscellaneous Chores
v3.14.0Compare Source
Features
RegExpsupport to PoolCluster (#3451) (2d5050d)v3.13.0Compare Source
Features
disableEval: add static parsers (#3365) (51da653)Bug Fixes
PromisePoolCluster.ofreturnsPromisePoolClusterinstead ofPoolNamespace(#3261) (be22202)VECTORpackets in static parser (#3379) (603c246)v3.12.0Compare Source
Features
restoreNodeTimeoutimplementation (#3218) (9a38601)v3.11.5Compare Source
Bug Fixes
v2requirescommonjstype explicitly (#3209) (cdc9415)v3.11.4Compare Source
Bug Fixes
v3.11.3Compare Source
Bug Fixes
v3.11.2Compare Source
Bug Fixes
v3.11.1Compare Source
Bug Fixes
getConnection(#3017) (ab7c49f), closes #1381config.maxIdle(#3022) (b091cf4)v3.11.0Compare Source
Features
v3.10.3Compare Source
Bug Fixes
v3.10.2Compare Source
Bug Fixes
field.string()withqueryandexecute(#2820) (27e38ea)v3.10.1Compare Source
Bug Fixes
v3.10.0Compare Source
Features
Bug Fixes
v3.9.9Compare Source
Bug Fixes
v3.9.8Compare Source
Bug Fixes
jonServerPublicKeytoonServerPublicKey(#2699) (8b5f691)v3.9.7Compare Source
Bug Fixes
v3.9.6Compare Source
Bug Fixes
v3.9.5Compare Source
Bug Fixes
v3.9.4Compare Source
Bug Fixes
v3.9.3Compare Source
Bug Fixes
v3.9.2Compare Source
Bug Fixes
v3.9.1Compare Source
Bug Fixes
v3.9.0Compare Source
Features
executemethod (#2398) (baaa92a)v3.8.0Compare Source
Features
Bug Fixes
for await(#2389) (af47148)v3.7.1Compare Source
Bug Fixes
v3.7.0Compare Source
Features
v3.6.5Compare Source
Bug Fixes
v3.6.4Compare Source
Bug Fixes
ConnectionOptions(#2288) (5cd7639)v3.6.3Compare Source
Bug Fixes
v3.6.2Compare Source
Bug Fixes
v3.6.1Compare Source
Bug Fixes
v3.6.0Compare Source
Features
infileStreamFactoryoption (#2159) (5bed0f8)v3.5.2Compare Source
Bug Fixes
v3.5.1Compare Source
Bug Fixes
ResultSetHeader[]toqueryandexecute(f649486)v3.5.0Compare Source
Features
v3.4.5Compare Source
Bug Fixes
v3.4.4Compare Source
Bug Fixes
ProcedureCallPackettoexecuteoverloads (3566ef7)ProcedureCallPackettoqueryoverloads (352c3bc)ProcedureCallPacketto promise-basedexecuteoverloads (8292416)ProcedureCallPacketto promise-basedqueryoverloads (0f31a41)ProcedureCallPackettypings (09ad1d2)v3.4.3Compare Source
Bug Fixes
v3.4.2Compare Source
Bug Fixes
v3.4.1Compare Source
Bug Fixes
createPooluri overload (98623dd)PoolClustertypings (3902ca6)PoolClustertypings (7f38496)parserCacheinpromise.js(7f35cf5)promise.js(4ce2c70)Typesconstant (86655ec)Charsetsconstants (01f77a0)CharsetToEncodingconstants (609229a)parserCache(891a523)Typesconstant (04601dd)Charsetsconstants (51c4196)v3.4.0Compare Source
Features
v3.3.5Compare Source
Bug Fixes
createPoolConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.