HIGH
GHSA-xqg8-cv3h-xppv
SQL Injection in sequelize
Quick fix
GHSA-xqg8-cv3h-xppv — sequelize: upgrade to the fixed version with the command below.
npm install sequelize@2.0.0-rc8Details
Versions 2.0.0-rc-7 and earlier of `sequelize` are affected by a SQL injection vulnerability when user input is passed into the order parameter.
## Proof of Concept
```javascript Test.findAndCountAll({ where: { id :1 }, order : [['id', 'UNTRUSTED USER INPUT']] }) ```
## Recommendation
Update to version 2.0.0-rc8 or later
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-1369[ADVISORY]
- https://github.com/sequelize/sequelize/issues/2906[WEB]
- https://github.com/sequelize/sequelize/pull/2919[WEB]
- https://github.com/advisories/GHSA-xqg8-cv3h-xppv[ADVISORY]
- https://github.com/sequelize/sequelize[PACKAGE]
- https://www.npmjs.com/advisories/33[WEB]
- http://www.openwall.com/lists/oss-security/2015/01/23/2[WEB]