QID 981439
QID 981439: Nodejs (npm) Security Update for sequelize (GHSA-2777-2vq8-c4v4)
Versions of `sequelize` prior to 5.3.0 (excluding v3 and v4) are vulnerable to SQL Injection. PostgreSQL option`standard_conforming_strings` is not set to `on` by default, which may allow attackers to inject SQL statements due to poor handling of backslashes in string literals.
## Recommendation
Upgrade to version 5.3.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2777-2vq8-c4v4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2777-2vq8-c4v4 -
github.com/advisories/GHSA-2777-2vq8-c4v4
CVEs related to QID 981439
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2777-2vq8-c4v4 | sequelize |
|