Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2020-15250 Vulnerability in maven package junit:junit
CVE-2022-24999 Vulnerability in maven package org.webjars.bower:qs
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2021-32769 Vulnerability in maven package io.micronaut:micronaut-core
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services