CVE-2019-10752
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sequelizejs/sequelize
- Source
- report@snyk.io
References
- https://github.com/sequelize/sequelize/commit/9bd0bc1%2C
- https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541ePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751%2C
- https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751Exploit, Third Party Advisory
- https://github.com/sequelize/sequelize/commit/9bd0bc1%2C
- https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541ePatch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751%2C
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.