UNKNOWN npm
SQL Injection in sequelize
GHSA-xqg8-cv3h-xppv · CVE-2015-1369
Published · Modified
Description
Versions 2.0.0-rc-7 and earlier of sequelize are affected by a SQL injection vulnerability when user input is passed into the order parameter.
Proof of Concept
Test.findAndCountAll({
where: { id :1 },
order : [['id', 'UNTRUSTED USER INPUT']]
})
Recommendation
Update to version 2.0.0-rc8 or later
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2015-1369
- WEB https://github.com/sequelize/sequelize/issues/2906
- WEB https://github.com/sequelize/sequelize/pull/2919
- ADVISORY https://github.com/advisories/GHSA-xqg8-cv3h-xppv
- PACKAGE https://github.com/sequelize/sequelize
- WEB https://www.npmjs.com/advisories/33
- WEB http://www.openwall.com/lists/oss-security/2015/01/23/2
Ready to move
Start Securing
Free, no credit card | First findings in minutes