VDB
Sign up
MEDIUM5.3

GHSA-8c25-f3mj-v6h8

Sequelize information disclosure vulnerability

Quick fix

GHSA-8c25-f3mj-v6h8 — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@6.28.1

Details

Due to improper input filtering in the sequelize js library, can malicious queries lead to sensitive information disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 6.28.1
Fixnpm install sequelize@6.28.1
npm/@sequelize/core
Introduced in: 0Fixed in: 7.0.0-alpha.20
Fixnpm install @sequelize/core@7.0.0-alpha.20

References