HIGH7.5
GHSA-2777-2vq8-c4v4
SQL Injection in sequelize
Quick fix
GHSA-2777-2vq8-c4v4 — sequelize: upgrade to the fixed version with the command below.
npm install sequelize@5.3.0Details
Versions of `sequelize` prior to 5.3.0 (excluding v3 and v4) are vulnerable to SQL Injection. PostgreSQL option`standard_conforming_strings` is not set to `on` by default, which may allow attackers to inject SQL statements due to poor handling of backslashes in string literals.
## Recommendation
Upgrade to version 5.3.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-11069[ADVISORY]
- https://github.com/sequelize/sequelize/pull/10746[WEB]
- https://github.com/sequelize/sequelize/pull/10746/files[WEB]
- https://github.com/sequelize/sequelize/commit/850c7fd04669e0fef9238b6dc4f8d6ee93ed71e9[WEB]
- https://github.com/sequelize/sequelize[PACKAGE]
- https://github.com/sequelize/sequelize/blob/98cb17c17f73e2aa1792aa5a1d31216ba984b456/lib/dialects/postgres/connection-manager.js#L158-L160[WEB]
- https://github.com/sequelize/sequelize/releases/tag/v5.3.0[WEB]
- https://snyk.io/vuln/SNYK-JS-SEQUELIZE-174167[WEB]