Описание
Knex.js has a limited SQL injection vulnerability
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. This vulnerability has been fixed in version 2.4.0.
Пакеты
Наименование
knex
npm
Затронутые версииВерсия исправления
< 2.4.0
2.4.0
Связанные уязвимости
CVSS3: 7.5
nvd
около 3 лет назад
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.