Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
References
Link | Resource |
---|---|
https://github.com/sequelize/sequelize/blob/98cb17c17f73e2aa1792aa5a1d31216ba984b456/lib/dialects/postgres/connection-manager.js#L158-L160 | Third Party Advisory |
https://github.com/sequelize/sequelize/commit/850c7fd04669e0fef9238b6dc4f8d6ee93ed71e9 | |
https://github.com/sequelize/sequelize/pull/10746/files | Patch Third Party Advisory |
https://github.com/sequelize/sequelize/releases/tag/v5.3.0 | Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-04-10T00:00:00
Updated: 2023-11-17T22:14:20.995637
Reserved: 2019-04-10T00:00:00
Link: CVE-2019-11069
JSON object: View
NVD Information
Status : Modified
Published: 2019-04-10T21:29:01.573
Modified: 2023-11-17T23:15:07.300
Link: CVE-2019-11069
JSON object: View
Redhat Information
No data.
CWE