QID 983933
QID 983933: Nodejs (npm) Security Update for waterline-sequel (GHSA-cgpp-wm2h-6hqx)
Affected versions of `waterline-sequel` are vulnerable to SQL injection in cases where user input is passed into the `like`, `contains`, `startsWith`, or `endsWith` methods. ## Recommendation Upgrade to at least version 0.5.1
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cgpp-wm2h-6hqx for updates pertaining to this vulnerability.
Vendor References
- GHSA-cgpp-wm2h-6hqx -
github.com/advisories/GHSA-cgpp-wm2h-6hqx
CVEs related to QID 983933
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cgpp-wm2h-6hqx | waterline-sequel |
|