Skip to content

Update dependency mysql2 to v3.9.8 [SECURITY]#184

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-mysql2-vulnerability
Open

Update dependency mysql2 to v3.9.8 [SECURITY]#184
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-mysql2-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Apr 12, 2024

This PR contains the following updates:

Package Change Age Confidence
mysql2 (source) 3.9.33.9.8 age confidence

GitHub Vulnerability Alerts

CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

CVE-2024-21509

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

CVE-2024-21511

Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

CVE-2024-21512

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using nestTables.


Release Notes

sidorares/node-mysql2 (mysql2)

v3.9.8

Compare Source

Bug Fixes
  • security: sanitize fields and tables when using nestTables (#​2702) (efe3db5)
  • support deno + caching_sha2_password FULL_AUTHENTICATION_PACKET flow (#​2704) (2e03694)
  • typings: typo from jonServerPublicKey to onServerPublicKey (#​2699) (8b5f691)

v3.9.7

Compare Source

Bug Fixes
  • security: sanitize timezone parameter value to prevent code injection (#​2608) (7d4b098)

v3.9.6

Compare Source

Bug Fixes
  • binary parser sometimes reads out of packet bounds when results contain null and typecast is false (#​2601) (705835d)

v3.9.5

Compare Source

Bug Fixes

v3.9.4

Compare Source

Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from c4b4ccc to cd981c9 Compare April 15, 2024 06:48
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from cd981c9 to ba9f0c5 Compare April 22, 2024 07:47
@renovate renovate bot changed the title Update dependency mysql2 to v3.9.4 [SECURITY] Update dependency mysql2 to v3.9.7 [SECURITY] Apr 24, 2024
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from ba9f0c5 to ebd9e13 Compare April 24, 2024 01:44
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from c9ca1d8 to 35e13cc Compare May 13, 2024 03:23
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 35e13cc to 01137d5 Compare May 21, 2024 04:36
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 01137d5 to 971f0e9 Compare May 30, 2024 23:08
@renovate renovate bot changed the title Update dependency mysql2 to v3.9.7 [SECURITY] Update dependency mysql2 to v3.9.8 [SECURITY] May 30, 2024
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 971f0e9 to 7c78f4e Compare June 3, 2024 09:46
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 7c78f4e to f85b1eb Compare June 10, 2024 12:12
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from f85b1eb to b6f5f16 Compare June 24, 2024 08:34
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from b6f5f16 to 87c4aa3 Compare July 8, 2024 08:41
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from d6a9656 to d6b76d3 Compare July 22, 2024 03:20
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from d6b76d3 to e0c0082 Compare July 29, 2024 03:39
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from c61fbcf to a6d96c8 Compare August 12, 2024 04:08
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from a6d96c8 to 5676ff4 Compare August 19, 2024 09:56
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from f8e8869 to 3f8b107 Compare September 2, 2024 04:39
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from f00b7ea to f2f31a1 Compare September 16, 2024 09:48
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from d5eddc9 to 804047c Compare September 30, 2024 03:16
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 3 times, most recently from 50d49e5 to d2a30bb Compare October 14, 2024 09:29
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 1e203dd to 3883eb0 Compare October 28, 2024 06:31
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from ab1d6cd to 61012b6 Compare February 17, 2025 06:24
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from eef6c44 to c46a067 Compare March 3, 2025 11:44
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 82bcbdb to dd88a3f Compare March 17, 2025 06:12
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from dd88a3f to 416efa7 Compare March 24, 2025 23:43
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 6c1747e to 1c62954 Compare April 7, 2025 10:29
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 1ae616c to 20c0f48 Compare April 21, 2025 09:47
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 20c0f48 to f71585c Compare May 12, 2025 15:37
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from c5de950 to 3230174 Compare June 2, 2025 16:20
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 3230174 to 770de7a Compare June 9, 2025 09:49
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 770de7a to ae4e31d Compare June 16, 2025 20:09
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 5bae241 to 65b2023 Compare June 30, 2025 10:10
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 65b2023 to 6bb56af Compare July 14, 2025 11:15
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 585d4cf to 05b1548 Compare July 28, 2025 05:54
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from 0fb33ad to ae70fcd Compare August 11, 2025 13:02
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from ae70fcd to 8476f90 Compare August 18, 2025 14:31
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch 2 times, most recently from e978970 to ab83b6d Compare September 15, 2025 04:28
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from ab83b6d to f1cf419 Compare September 22, 2025 13:43
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from f1cf419 to 1c3eb71 Compare October 6, 2025 04:55
@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 1c3eb71 to c626c48 Compare October 13, 2025 10:41
@coderabbitai
Copy link

coderabbitai bot commented Feb 2, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants