Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2022-41254 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2023-28155 Vulnerability in npm package request
CVE-2021-21297 Vulnerability in npm package @node-red/editor-api
CVE-2023-34238 Vulnerability in npm package gatsby
CVE-2022-24759 Vulnerability in npm package @chainsafe/libp2p-noise