-
CVSS Score
-The vulnerability stems from LOAD DATA LOCAL INFILE being enabled by default. The commit patching this adds a 'localInfile' option and modifies ConnectionConfig.getDefaultFlags to conditionally disable LOCAL_FILES. In the vulnerable version (2.17.1):
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mysql | npm | = 2.17.1 | 2.18.0 |
Ongoing coverage of React2Shell