Update dependency mysql2 to v3.9.8 [SECURITY]#144
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
Update dependency mysql2 to v3.9.8 [SECURITY]#144renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
9c9ce61 to
c472e32
Compare
6d8151d to
b1d1dd8
Compare
b1d1dd8 to
982577c
Compare
982577c to
0811205
Compare
0811205 to
a6f5b30
Compare
0b8f3b7 to
3f58da5
Compare
e28cd08 to
a204a59
Compare
d558833 to
75942fc
Compare
75942fc to
151c113
Compare
151c113 to
4642c83
Compare
4642c83 to
69de1f5
Compare
2be24ec to
d6ebbcb
Compare
d72586e to
549d282
Compare
549d282 to
0d565bf
Compare
0d565bf to
7dcd813
Compare
7dcd813 to
ebb3780
Compare
ebb3780 to
fb29eb7
Compare
fb29eb7 to
7871fc8
Compare
7871fc8 to
15e45df
Compare
15e45df to
b1038c2
Compare
a4e9ec5 to
7b66aab
Compare
7b66aab to
5f1da44
Compare
5f1da44 to
4676b4a
Compare
4676b4a to
ae98e68
Compare
ae98e68 to
ee1efd8
Compare
ee1efd8 to
39a116a
Compare
39a116a to
e306a64
Compare
703e2f6 to
bf620fa
Compare
bf620fa to
c5214ab
Compare
c5214ab to
b168bb1
Compare
b168bb1 to
2260445
Compare
2260445 to
0b72cda
Compare
53da44d to
ff2e40e
Compare
ff2e40e to
d888767
Compare
d888767 to
40d8a96
Compare
40d8a96 to
a7a5b74
Compare
2bf22ae to
29d41f9
Compare
29d41f9 to
f51f3c7
Compare
f51f3c7 to
0da5bed
Compare
0da5bed to
9fac06a
Compare
9fac06a to
7f85a78
Compare
7f85a78 to
583178f
Compare
583178f to
0e80104
Compare
0e80104 to
b64c84f
Compare
b64c84f to
fe7a334
Compare
fe7a334 to
7606d85
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.9.3→3.9.8GitHub Vulnerability Alerts
CVE-2024-21509
Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through
parserFnintext_parser.jsandbinary_parser.js.CVE-2024-21508
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the
readCodeForfunction due to improper validation of thesupportBigNumbersandbigNumberStringsvalues.CVE-2024-21511
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
CVE-2024-21512
Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.
Release Notes
sidorares/node-mysql2 (mysql2)
v3.9.8Compare Source
Bug Fixes
jonServerPublicKeytoonServerPublicKey(#2699) (8b5f691)v3.9.7Compare Source
Bug Fixes
v3.9.6Compare Source
Bug Fixes
v3.9.5Compare Source
Bug Fixes
v3.9.4Compare Source
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.