CRITICAL9.8
GHSA-5hq7-j5wq-p227
feathers-sequelize vulnerable to SQL injection due to improper parameter filtering
Quick fix
GHSA-5hq7-j5wq-p227 — feathers-sequelize: upgrade to the fixed version with the command below.
npm install feathers-sequelize@6.3.4Details
feathers-sequelize is vulnerable to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-29822[ADVISORY]
- https://github.com/feathersjs-ecosystem/feathers-sequelize/commit/0f2d85f0b2d556f2b6c70423dcebdbd29d95e3dc[WEB]
- https://csirt.divd.nl/CVE-2022-29822[WEB]
- https://csirt.divd.nl/DIVD-2022-00020[WEB]
- https://csirt.divd.nl/cases/DIVD-2022-00020[WEB]
- https://csirt.divd.nl/cves/CVE-2022-29822[WEB]
- https://github.com/feathersjs-ecosystem/feathers-sequelize[PACKAGE]