QID 983201
QID 983201: Nodejs (npm) Security Update for mysql (GHSA-fvq6-55gv-jx9f)
Versions of `mysql` prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in the `mysql.escape()` function, which does not properly escape object keys.
## Recommendation
Update to version 2.0.0-alpha8 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fvq6-55gv-jx9f for updates pertaining to this vulnerability.
Vendor References
- GHSA-fvq6-55gv-jx9f -
github.com/advisories/GHSA-fvq6-55gv-jx9f
CVEs related to QID 983201
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fvq6-55gv-jx9f | mysql |
|