CVE-2019-11069
Summary
| CVE | CVE-2019-11069 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 21:29:00 UTC |
| Updated | 2023-11-17 23:15:00 UTC |
| Description | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release v5.3.0 · sequelize/sequelize · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| github.com/sequelize/sequelize/commit/850c7fd04669e0fef9238b6dc4f8d6ee93... |
|
github.com |
|
| fix(postgres): check and enable standard conforming strings when required by sushantdhiman · Pull Request #10746 · sequelize/sequelize · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| sequelize/connection-manager.js at 98cb17c17f73e2aa1792aa5a1d31216ba984b456 · sequelize/sequelize · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981439 Nodejs (npm) Security Update for sequelize (GHSA-2777-2vq8-c4v4)