VDB
Sign up
CRITICAL9.9

GHSA-vqfx-gj96-3w95

Unsafe fall-through in getWhereConditions

Quick fix

GHSA-vqfx-gj96-3w95 — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@6.28.1

Details

### Impact

Providing an invalid value to the `where` option of a query caused Sequelize to ignore that option instead of throwing an error.

A finder call like the following did not throw an error:

```ts User.findAll({ where: new Date(), }); ```

As this option is typically used with plain javascript objects, be aware that this only happens at the top level of this option.

### Patches

This issue has been patched in [`sequelize@6.28.1`](https://github.com/sequelize/sequelize/pull/15699) & [`@sequelize/core@7.0.0.alpha-20`](https://github.com/sequelize/sequelize/pull/15375)

### References

A discussion thread about this issue is open at https://github.com/sequelize/sequelize/discussions/15698

CVE: CVE-2023-22579 Snyk: https://security.snyk.io/vuln/SNYK-JS-SEQUELIZE-3324090

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 6.28.1
Fixnpm install sequelize@6.28.1
npm/@sequelize/core
Introduced in: 0Fixed in: 7.0.0-alpha.20
Fixnpm install @sequelize/core@7.0.0-alpha.20

References