QID 980703
QID 980703: Nodejs (npm) Security Update for sequelize (GHSA-5v9h-q3gj-c32x)
Affected versions of `sequelize` are vulnerable to SQL Injection in Models that have fields with the `GEOMETRY` DataType. This vulnerability occurs because single quotes in document values are not escaped for GeoJSON documents using `ST_GeomFromGeoJSON`, and MySQL GeoJSON documents using `GeomFromText`.
## Recommendation
Update to version 3.23.6 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5v9h-q3gj-c32x for updates pertaining to this vulnerability.
Vendor References
- GHSA-5v9h-q3gj-c32x -
github.com/advisories/GHSA-5v9h-q3gj-c32x
CVEs related to QID 980703
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5v9h-q3gj-c32x | sequelize |
|