Executive brief
The Node.js mysql package before version 2.14.0 contains a vulnerability where uninitialized memory is transmitted over the network when a numeric value is provided as a database password. An attacker with control over the password parameter could extract sensitive information from the application's memory. This issue only affects Node.js versions below 6.0.0 due to protective checks added in newer Node.js releases.
Technical details
The vulnerability is a memory disclosure issue (CWE-201) in the mysql Node.js package affecting versions 2.0.0-alpha8 through 2.13.x. When a numeric value is passed as the password parameter during database connection creation, the affected code allocates a buffer without proper initialization and sends it over the network during the authentication handshake. The vulnerability is triggered only when connecting to MySQL servers and the password parameter is of numeric type rather than a string. Network access to the vulnerable application is required; no authentication is needed from the attacker's perspective. The flaw was fixed in version 2.14.0 by using the safe-buffer module to ensure proper buffer initialization. The vulnerability only manifests in Node.js versions below 6.0.0, as newer versions include runtime protections that throw an error when attempting to create an uninitialized buffer.
Affected products
- npm mysql 2.0.0-alpha8 through 2.13.x
Timeline
- 2019-05-23: disclosed