Description
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
Remediation
References
https://github.com/felixge/node-mysql/issues/342
https://nodesecurity.io/advisories/66
Related Vulnerabilities
CVE-2018-20190 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2019-10744 Vulnerability in npm package @sailshq/lodash
CVE-2017-1000427 Vulnerability in maven package org.webjars:marked
CVE-2020-7787 Vulnerability in npm package react-adal
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project