Описание
Sequelize information disclosure vulnerability
Due to improper input filtering in the sequelize js library, can malicious queries lead to sensitive information disclosure.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-22580
- https://github.com/sequelize/sequelize/pull/15375
- https://github.com/sequelize/sequelize/pull/15699
- https://csirt.divd.nl/CVE-2023-22580
- https://csirt.divd.nl/DIVD-2022-00020
- https://github.com/sequelize/sequelize/releases/tag/v6.28.1
- https://github.com/sequelize/sequelize/releases/tag/v7.0.0-alpha.20
Пакеты
Наименование
sequelize
npm
Затронутые версииВерсия исправления
< 6.28.1
6.28.1
Наименование
@sequelize/core
npm
Затронутые версииВерсия исправления
< 7.0.0-alpha.20
7.0.0-alpha.20
Связанные уязвимости
CVSS3: 5.3
nvd
почти 3 года назад
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.