VDB
Sign up
HIGH7.5

GHSA-9c2p-jw8p-f84v

SQL Injection in sequelize

Quick fix

GHSA-9c2p-jw8p-f84v — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@3.20.0

Details

Affected versions of `sequelize` cast arrays to strings and fail to properly escape the resulting SQL statement, resulting in a SQL injection vulnerability.

## Proof of Concept In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped.

Example Query: ``` database.query('SELECT * FROM TestTable WHERE Name IN (:names)', { replacements: { names: directCopyOfUserInput } }); ```

If the user inputs the value of `:names` as: ``` ["test", "'); DELETE TestTable WHERE Id = 1 --')"] ```

The resulting SQL statement will be: ```sql SELECT Id FROM Table WHERE Name IN ('test', '\'); DELETE TestTable WHERE Id = 1 --') ``` As the backslash has no special meaning in PostgreSQL, MSSQL, or SQLite, the statement will delete the record in TestTable with an Id of 1.

## Recommendation

Update to version 3.20.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 3.20.0
Fixnpm install sequelize@3.20.0

References