PT-2019-12024 · Sequelize · Sequelize

Publicado

2019-10-29

·

Atualizado

2019-11-08

·

CVE-2019-10749

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sequelize versions prior to 3.35.1
Description The issue allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect. This may allow attackers to inject SQL statements and execute arbitrary SQL queries.
Recommendations For versions prior to 3.35.1, upgrade to version 3.35.1 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10749
GHSA-2598-2F59-RMHQ
SNYK-JS-SEQUELIZE-450222

Produtos afetados

Sequelize