fix(deps): update dependency sequelize to v4.44.4 [security]#31
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
fix(deps): update dependency sequelize to v4.44.4 [security]#31renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
607f72f to
b79c4d0
Compare
b79c4d0 to
f4d3cb3
Compare
f4d3cb3 to
4ad0368
Compare
4ad0368 to
198a235
Compare
198a235 to
12882d1
Compare
12882d1 to
ca9b101
Compare
ca9b101 to
aa8bfa1
Compare
aa8bfa1 to
05938ea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.39.0->4.44.4GitHub Vulnerability Alerts
CVE-2019-10752
Affected versions of
sequelizeare vulnerable to SQL Injection. The functionsequelize.json()incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query. Exploitation example:const Sequelize = require('sequelize');
const sequelize = new Sequelize({
dialect: 'sqlite',
storage: 'database.sqlite'
});
const TypeError = sequelize.define('TypeError', {
name: Sequelize.STRING,
});
TypeError.sync({force: true}).then(() => {
return TypeError.create({name: "SELECT tbl_name FROM sqlite_master"});
});