GHSA-v8fg-2rw7-q452
Sequelize: SQL Injection (Oracle DB)
Quick fix
GHSA-v8fg-2rw7-q452 — sequelize: upgrade to the fixed version with the command below.
npm install sequelize@6.37.4 Details
### Summary SQL Injection is possible with strings only **if dialect is set to `oracle`**. The vulnerability was confirmed on Sequelize v6.37.3.
### Details The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`.
```javascript } else if (dialect === 'oracle' && typeof val === 'string') { if (val.startsWith('TO_TIMESTAMP') || val.startsWith('TO_DATE')) { return val; } val = val.replace(/'/g, "''"); } ```
### PoC Suppose the application has the following code:
```javascript var result = await models.Student.findOne({ where: { firstName: req.query.firstName } }); ```
An attacker can inject arbitrary sql expressions.
`http://host/path?firstName=TO_DATE('0','Y')||'' OR 1=1--`
The resulted SQL will be:
```SQL SELECT ... WHERE "Student"."firstName" = TO_DATE('0','Y')||'' OR 1=1-- ORDER BY "Student"."id" OFFSET 0 ROWS FETCH NEXT 1 ROWS ONLY; ```
### Impact Data theft and tampering.
Are you affected?
Enter the version of the package you're using.