NA

CVE-2024-21511

Published: 23/04/2024 Updated: 23/04/2024

Vulnerability Summary

Versions of the package mysql2 prior to 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.