CRITICAL 10.0 npm
Duplicate advisory: Sequelize vulnerable to Improper Filtering of Special Elements
GHSA-8mwq-mj73-qv68
Published · Modified
Description
Duplicate advisory
This advisory has been withdrawn because it is a duplicate of GHSA-f598-mfpv-gmfx. This link is maintained to preserve external references.
Original Description
Due to improper attribute filtering in the sequelize js library, an attacker can peform SQL injections. This issue can be mitigated by not accepting untrusted input.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-22578
- WEB https://csirt.divd.nl/CVE-2023-22578
- WEB https://csirt.divd.nl/DIVD-2022-00020
- PACKAGE https://github.com/sequelize/sequelize
- WEB https://github.com/sequelize/sequelize/discussions/15694
- WEB https://github.com/sequelize/sequelize/releases/tag/v7.0.0-alpha.20
Ready to move
Start Securing
Free, no credit card | First findings in minutes