HIGH7.5
GHSA-4jv9-3563-23j3
Knex.js has a limited SQL injection vulnerability
Quick fix
GHSA-4jv9-3563-23j3 — knex: upgrade to the fixed version with the command below.
npm install knex@2.4.0Details
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. This vulnerability has been fixed in version 2.4.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-20018[ADVISORY]
- https://github.com/knex/knex/issues/1227[WEB]
- https://github.com/knex/knex/pull/5417[WEB]
- https://github.com/knex/knex/commit/e145322da92749be7749f9ade5b5f5a66d6586a4[WEB]
- https://github.com/knex/knex[PACKAGE]
- https://github.com/knex/knex/releases/tag/2.4.0[WEB]
- https://www.ghostccamm.com/blog/knex_sqli[WEB]