Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://nodesecurity.io/advisories/66
https://github.com/felixge/node-mysql/issues/342
Related Vulnerabilities
CVE-2017-16119 Vulnerability in maven package org.webjars.npm:fresh
CVE-2020-8124 Vulnerability in maven package org.webjars.npm:url-parse
CVE-2019-10785 Vulnerability in maven package org.webjars.bower:dojox
CVE-2020-28472 Vulnerability in maven package org.webjars.npm:aws-sdk
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common