Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon : character within a value of the attacker-crafted key.
{
"cwe_ids": [
"CWE-20"
],
"github_reviewed_at": "2024-04-12T13:49:53Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2024-04-10T05:15:48Z"
}