mysqljs / mysql

A pure node.js JavaScript Client implementing the MySQL protocol.
MIT License
18.28k stars 2.52k forks source link

CVE-2019-14939 #2471

Closed chillheart closed 3 years ago

chillheart commented 3 years ago

Hello,

The issue ( #2257 ) for CVE-2019-14939 was closed and no details were provided as to whether it was resolved or not in the latest versions of the library.

I found the following commit, however since we do not have the details around the original exploit, I cannot verify if this has been resolved.

337e87ae5fcea3667864197c65dc758517fcde06

Can you confirm that this has been resolved?

dougwilson commented 3 years ago

AFAIK there are no unresolved issues. If you are aware of any, have found that there are additional vectors against a previous onez or have found additional flaws either new or relating to a previous issue, please contact me following the security report procedure in the readme so I can work to evaluate the report and work together on any necessary fixes.

Thank you!