PT-2024-2756 · Mysql2 · Mysql2

Slonser

+1

·

Published

2024-04-11

·

Updated

2025-12-04

·

CVE-2024-21508

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mysql2 versions prior to 3.9.4
Description The issue is related to the readCodeFor function in the mysql2 package, which is vulnerable to Remote Code Execution (RCE) due to improper validation of the supportBigNumbers and bigNumberStrings values. This allows a remote attacker to execute arbitrary code.
Recommendations For versions prior to 3.9.4, update to version 3.9.4 or later to resolve the issue. As a temporary workaround, consider disabling the readCodeFor function until a patch is available. Restrict access to the mysql2 package to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02887
CVE-2024-21508
GHSA-FPW7-J2HG-69V5

Affected Products

Mysql2