QID 983153
QID 983153: Nodejs (npm) Security Update for sequelize (GHSA-98pq-pmw9-4gpm)
Affected versions of `sequelize` are vulnerable to SQL Injection in locations where user input is passed into the `limit` or `order` parameters of `sequelize` query calls, such as `findOne` or `findAll`.
## Recommendation
Update to version 3.17.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-98pq-pmw9-4gpm for updates pertaining to this vulnerability.
Vendor References
- GHSA-98pq-pmw9-4gpm -
github.com/advisories/GHSA-98pq-pmw9-4gpm
CVEs related to QID 983153
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-98pq-pmw9-4gpm | sequelize |
|