PT-2019-12164 · Postgresql · Sequelize

Published

2019-04-10

·

Updated

2023-11-17

·

CVE-2019-11069

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sequelize versions prior to 5.3.0
Description The issue arises from the improper handling of backslashes in string literals, potentially allowing attackers to inject SQL statements. This is due to the PostgreSQL option standard conforming strings not being set to on by default.
Recommendations Upgrade to version 5.3.0 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2019-11069
GHSA-2777-2VQ8-C4V4

Affected Products

Sequelize