QID 981641
QID 981641: Nodejs (npm) Security Update for knex (GHSA-58v4-qwx5-7f59)
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-58v4-qwx5-7f59 for updates pertaining to this vulnerability.
Vendor References
- GHSA-58v4-qwx5-7f59 -
github.com/advisories/GHSA-58v4-qwx5-7f59
CVEs related to QID 981641
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-58v4-qwx5-7f59 | knex |
|