Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2021-27292 Vulnerability in npm package ua-parser-js
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:element-connector
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika
CVE-2019-11819 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2022-24891 Vulnerability in maven package org.owasp.esapi:esapi