Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency mysql2 to v3.9.4 [SECURITY] #4435

Merged
merged 1 commit into from
Apr 12, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 12, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mysql2 (source) 3.6.3 -> 3.9.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-21507

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon : character within a value of the attacker-crafted key.

CVE-2024-21509

Versions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper user input sanitization passed through parserFn in text_parser.js and binary_parser.js.

CVE-2024-21508

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.


Release Notes

sidorares/node-mysql2 (mysql2)

v3.9.4

Compare Source

Bug Fixes

v3.9.3

Compare Source

Bug Fixes
  • security: improve cache key formation (#​2424) (0d54b0c)
    • Fixes a potential parser cache poisoning attack vulnerability reported by Vsevolod Kokorin (Slonser) of Solidlab
  • update Amazon RDS SSL CA cert (#​2131) (d9dccfd)

v3.9.2

Compare Source

Bug Fixes

v3.9.1

Compare Source

Bug Fixes

v3.9.0

Compare Source

Features

v3.8.0

Compare Source

Features
Bug Fixes

v3.7.1

Compare Source

Bug Fixes
  • add condition which allows code in callback to be reachable (#​2376) (8d5b903)

v3.7.0

Compare Source

Features

v3.6.5

Compare Source

Bug Fixes
  • add decodeuricomponent to parse uri encoded special characters in host, username, password and datbase keys (#​2277) (fe573ad)

v3.6.4

Compare Source

Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from a team as a code owner April 12, 2024 14:53
@renovate renovate bot added the Dependencies Pull requests that update a dependency file label Apr 12, 2024
@renovate renovate bot requested review from data-sync-user and removed request for a team April 12, 2024 14:53
Copy link

github-actions bot commented Apr 12, 2024

Size Change: 0 B

Total Size: 6.08 MB

ℹ️ View Unchanged
Filename Size
web/dist/1-1.****************.png 9.87 kB
web/dist/1-2.****************.png 7.66 kB
web/dist/1-3.****************.png 14.1 kB
web/dist/1-4.****************.png 24.4 kB
web/dist/1-5.****************.png 15.8 kB
web/dist/1-6.****************.png 12.3 kB
web/dist/1-red-copy.****************.svg 9.27 kB
web/dist/159.****************.js 8.26 kB
web/dist/159.****************.css 3.1 kB
web/dist/187.****************.js 5.6 kB
web/dist/187.****************.css 3.11 kB
web/dist/2-1.****************.png 7.09 kB
web/dist/2-2.****************.png 14.1 kB
web/dist/2-3.****************.png 10.3 kB
web/dist/2-4.****************.png 9.87 kB
web/dist/2-5.****************.png 8.42 kB
web/dist/262.****************.js 5.29 kB
web/dist/262.****************.css 3.25 kB
web/dist/372.****************.css 773 B
web/dist/372.****************.js 2.94 kB
web/dist/424.****************.css 9.52 kB
web/dist/424.****************.js 16 kB
web/dist/440.****************.js 5.97 kB
web/dist/440.****************.css 2.74 kB
web/dist/490.****************.js 5.82 kB
web/dist/490.****************.css 2.23 kB
web/dist/529.****************.css 1.28 kB
web/dist/529.****************.js 907 B
web/dist/569.****************.css 745 B
web/dist/616.****************.js 1.47 kB
web/dist/616.****************.css 494 B
web/dist/655.****************.js 5.34 kB
web/dist/662.****************.js 5.47 kB
web/dist/662.****************.css 3.18 kB
web/dist/782.****************.js 6.5 kB
web/dist/785.****************.css 5.3 kB
web/dist/785.****************.js 8.11 kB
web/dist/791.****************.js 5.74 kB
web/dist/791.****************.css 2.7 kB
web/dist/814.****************.js 16.2 kB
web/dist/814.****************.css 4.63 kB
web/dist/863.****************.js 487 B
web/dist/863.****************.css 494 B
web/dist/877.****************.css 2.09 kB
web/dist/877.****************.js 3.23 kB
web/dist/883.****************.css 3.68 kB
web/dist/883.****************.js 6.42 kB
web/dist/956.****************.css 1.35 kB
web/dist/956.****************.js 1.69 kB
web/dist/964.****************.js 620 B
web/dist/964.****************.css 394 B
web/dist/alert.****************.svg 748 B
web/dist/background-wave-error.****************.svg 403 B
web/dist/background-wave-success.****************.svg 548 B
web/dist/background-wave.****************.svg 280 B
web/dist/challenge-mtn-post.****************.svg 3.35 kB
web/dist/challenge-mtn-pre.****************.svg 3.41 kB
web/dist/checkmark.****************.svg 314 B
web/dist/chevron-left.****************.svg 291 B
web/dist/chevron-right.****************.svg 293 B
web/dist/chrome-color.****************.svg 1.97 kB
web/dist/close-black.****************.svg 820 B
web/dist/close.****************.svg 819 B
web/dist/common-voice-mars-neutral.****************.png 125 kB
web/dist/contact.****************.svg 975 B
web/dist/contribute.****************.png 599 kB
web/dist/cv-logo-black.****************.svg 2.36 kB
web/dist/cv-logo-white.****************.svg 2.9 kB
web/dist/dashboard.****************.png 954 kB
web/dist/datasets-intro-background-triangle.****************.svg 444 B
web/dist/datasets-intro-background.****************.svg 502 B
web/dist/deepspeech.****************.png 10.7 kB
web/dist/deepspeech@2x.****************.png 31.6 kB
web/dist/deepspeech@3x.****************.png 63.2 kB
web/dist/discourse.****************.png 16.4 kB
web/dist/discourse.****************.svg 479 B
web/dist/discourse@2x.****************.png 44.7 kB
web/dist/discourse@3x.****************.png 73.9 kB
web/dist/donate-banner-desktop-coral.****************.svg 597 B
web/dist/donate-banner-desktop-pink.****************.svg 597 B
web/dist/donate-bg1.****************.png 57.8 kB
web/dist/donate-bg2.****************.png 43.4 kB
web/dist/down-arrow.****************.svg 394 B
web/dist/email-bg-light.****************.png 12.5 kB
web/dist/email-bg-md-light.****************.svg 912 B
web/dist/email-bg-md.****************.svg 1.1 kB
web/dist/email-bg-partnerships.****************.png 287 kB
web/dist/email-bg.****************.png 4.22 kB
web/dist/exclamation.****************.svg 524 B
web/dist/fading.****************.svg 321 B
web/dist/feedback.****************.png 26.4 kB
web/dist/feedback@2x.****************.png 82.6 kB
web/dist/feedback@3x.****************.png 269 kB
web/dist/ff-color.****************.svg 4.3 kB
web/dist/github.****************.svg 848 B
web/dist/globe_black.****************.svg 948 B
web/dist/globe.****************.svg 947 B
web/dist/grid.****************.svg 387 B
web/dist/guidelines-waves-footer-small.****************.png 11.8 kB
web/dist/guidelines-waves-footer.****************.png 154 kB
web/dist/guidelines-waves.****************.png 225 kB
web/dist/happy-mars@2x.****************.png 22.9 kB
web/dist/hex-done.****************.svg 335 B
web/dist/hex.****************.svg 301 B
web/dist/home.****************.svg 505 B
web/dist/ibm.****************.svg 498 B
web/dist/keyboard.****************.svg 356 B
web/dist/languages/test.json 20 B
web/dist/lenovo.****************.svg 926 B
web/dist/librispeech.****************.png 155 B
web/dist/light-waves.****************.svg 1.7 kB
web/dist/listen-bg.****************.svg 1.98 kB
web/dist/listen.****************.svg 1.8 kB
web/dist/mail.****************.svg 1 kB
web/dist/main.****************.js 42.3 kB
web/dist/main.****************.css 9.89 kB
web/dist/mars-avatar.****************.svg 1.36 kB
web/dist/mars-email-success.****************.svg 7.76 kB
web/dist/mars-request.****************.svg 7.05 kB
web/dist/mars-sad.****************.svg 6.24 kB
web/dist/mars.****************.svg 2.7 kB
web/dist/mesh.****************.svg 484 B
web/dist/mic.****************.svg 432 B
web/dist/mozilla-common-voice_foundation-academia.****************.png 10.2 kB
web/dist/mozilla-common-voice_foundation-community.****************.png 10.9 kB
web/dist/mozilla-common-voice_foundation-corporates.****************.png 11.9 kB
web/dist/mozilla-common-voice_foundation-foundations.****************.png 12.3 kB
web/dist/mozilla-common-voice_foundation-governments.****************.png 7.51 kB
web/dist/mozilla-common-voice_foundation-mars_small.****************.png 24 kB
web/dist/mozilla-common-voice_foundation-mars.****************.png 49.2 kB
web/dist/mozilla-common-voice_foundation-small-business.****************.png 10.6 kB
web/dist/mozilla-logo.****************.svg 902 B
web/dist/mozilla.****************.svg 465 B
web/dist/play.****************.svg 2.15 kB
web/dist/plus.****************.svg 330 B
web/dist/question-mark.****************.svg 766 B
web/dist/red-robot.****************.svg 1.1 MB
web/dist/releases/cv-corpus-1.json 2.92 kB
web/dist/releases/cv-corpus-10.0-2022-07-04.json 14.9 kB
web/dist/releases/cv-corpus-10.0-delta-2022-07-04.json 7.89 kB
web/dist/releases/cv-corpus-11.0-2022-09-21.json 15.4 kB
web/dist/releases/cv-corpus-2.json 4.35 kB
web/dist/releases/cv-corpus-3.json 4.45 kB
web/dist/releases/cv-corpus-4-2019-12-10.json 5.52 kB
web/dist/releases/cv-corpus-5-2020-06-22.json 9.96 kB
web/dist/releases/cv-corpus-5-singleword.json 2.53 kB
web/dist/releases/cv-corpus-5.1-2020-06-22.json 9.97 kB
web/dist/releases/cv-corpus-5.1-singleword.json 2.52 kB
web/dist/releases/cv-corpus-6.0-2020-12-11.json 10.7 kB
web/dist/releases/cv-corpus-6.0-singleword.json 3.43 kB
web/dist/releases/cv-corpus-6.1-2020-12-11.json 10.9 kB
web/dist/releases/cv-corpus-6.1-singleword.json 3.52 kB
web/dist/releases/cv-corpus-7.0-2021-07-21.json 13.4 kB
web/dist/releases/cv-corpus-7.0-singleword.json 3.63 kB
web/dist/releases/cv-corpus-8.0-2022-01-19.json 13.6 kB
web/dist/releases/cv-corpus-9.0-2022-04-27.json 14.8 kB
web/dist/review-waves.****************.png 20.4 kB
web/dist/robot.****************.png 52.1 kB
web/dist/runtime.****************.js 2.59 kB
web/dist/safari-color.****************.svg 8.71 kB
web/dist/sap.****************.svg 849 B
web/dist/search.****************.svg 428 B
web/dist/segment-dots.****************.svg 471 B
web/dist/sodedif.****************.png 1.95 kB
web/dist/speak-bg.****************.svg 1.98 kB
web/dist/speak.****************.svg 1.69 kB
web/dist/star.****************.svg 557 B
web/dist/stars-disabled.****************.svg 2.09 kB
web/dist/stars.****************.svg 2.13 kB
web/dist/success.****************.svg 1.47 kB
web/dist/support.****************.svg 1.94 kB
web/dist/tatoeba.****************.png 21 kB
web/dist/ted.****************.png 172 B
web/dist/upload.****************.svg 551 B
web/dist/vendors.****************.js 378 kB
web/dist/voxforge.****************.png 10.5 kB
web/dist/wave-1.****************.svg 444 B
web/dist/wave-2.****************.svg 816 B
web/dist/wave-3.****************.svg 464 B
web/dist/wave-blue.****************.svg 4.32 kB
web/dist/wave-eq.****************.svg 1.03 kB
web/dist/wave-fading.****************.svg 341 B
web/dist/wave-grey.****************.svg 1.9 kB
web/dist/wave-top.****************.png 5.28 kB
web/dist/wave.****************.png 196 kB
web/dist/wave.****************.svg 1.07 kB
web/dist/waves-md.****************.svg 1.66 kB
web/dist/waves-small.****************.png 35.1 kB
web/dist/waves.****************.svg 1.85 kB
web/dist/waves.****************.png 33.4 kB
web/dist/waves@2x.****************.png 113 kB
web/dist/waves@3x.****************.png 227 kB

compressed-size-action

@renovate renovate bot force-pushed the renovate/npm-mysql2-vulnerability branch from 819bfac to c250709 Compare April 12, 2024 16:11
@renovate renovate bot changed the title Update dependency mysql2 to v3 [SECURITY] Update dependency mysql2 to v3.9.4 [SECURITY] Apr 12, 2024
@renovate renovate bot merged commit 4a5e2ce into main Apr 12, 2024
2 checks passed
@renovate renovate bot deleted the renovate/npm-mysql2-vulnerability branch April 12, 2024 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants