PT-2019-12164 · Postgresql · Sequelize

CVE-2019-11069

·

Publicado

2019-04-10

·

Atualizado

2023-11-17

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sequelize versions prior to 5.3.0
Description The issue arises from the improper handling of backslashes in string literals, potentially allowing attackers to inject SQL statements. This is due to the PostgreSQL option standard conforming strings not being set to on by default.
Recommendations Upgrade to version 5.3.0 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11069
GHSA-2777-2VQ8-C4V4

Produtos afetados

Sequelize