Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
References
Link | Resource |
---|---|
https://github.com/sequelize/sequelize/commit/9bd0bc1%2C | |
https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751 | Exploit Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751%2C |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: snyk
Published: 2019-10-17T18:12:43
Updated: 2019-10-17T18:12:43
Reserved: 2019-04-03T00:00:00
Link: CVE-2019-10752
JSON object: View
NVD Information
Status : Modified
Published: 2019-10-17T19:15:10.420
Modified: 2023-11-07T03:02:33.350
Link: CVE-2019-10752
JSON object: View
Redhat Information
No data.
CWE