VDB
Sign up
HIGH

GHSA-xqg8-cv3h-xppv

SQL Injection in sequelize

Quick fix

GHSA-xqg8-cv3h-xppv — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@2.0.0-rc8

Details

Versions 2.0.0-rc-7 and earlier of `sequelize` are affected by a SQL injection vulnerability when user input is passed into the order parameter.

## Proof of Concept

```javascript Test.findAndCountAll({ where: { id :1 }, order : [['id', 'UNTRUSTED USER INPUT']] }) ```

## Recommendation

Update to version 2.0.0-rc8 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 2.0.0-rc8
Fixnpm install sequelize@2.0.0-rc8

References