QID 983177
QID 983177: Nodejs (npm) Security Update for sequelize (GHSA-x2jc-pwfj-h9p3)
Affected versions of `sequelize` use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.
## Recommendation
Update to version 1.7.0-alpha3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x2jc-pwfj-h9p3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x2jc-pwfj-h9p3 -
github.com/advisories/GHSA-x2jc-pwfj-h9p3
CVEs related to QID 983177
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x2jc-pwfj-h9p3 | sequelize |
|