Skip to content

CVE: 2017-3523 found in MySQL Connector/J - Version: 5.1.35 [JAVA] #839

@github-actions

Description

@github-actions

Veracode Software Composition Analysis

Attribute Details
Library MySQL Connector/J
Description JDBC Type 4 driver for MySQL
Language JAVA
Vulnerability Improper Automatic Deserialization
Vulnerability description mysql-connector-java is vulnerable to deserialization attacks. The vulnerability exists as there is an improper automatic deserialization issue in the getNativeConvertToString function of ResultSetImpl.
CVE 2017-3523
CVSS score 6
Vulnerability present in version/s 5.1.1-5.1.40
Found library version/s 5.1.35
Vulnerability fixed in version 5.1.41
Library latest version 8.0.30
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions