fix(deps): update dependency sequelize to v4.44.4 [security]#31
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency sequelize to v4.44.4 [security]#31renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
December 14, 2019 23:47
607f72f to
b79c4d0
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
December 22, 2019 07:51
b79c4d0 to
f4d3cb3
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
January 18, 2020 23:56
f4d3cb3 to
4ad0368
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
March 14, 2020 22:56
4ad0368 to
198a235
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
April 28, 2020 05:55
198a235 to
12882d1
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
July 2, 2020 04:51
12882d1 to
ca9b101
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
October 29, 2020 11:56
ca9b101 to
aa8bfa1
Compare
renovate
Bot
force-pushed
the
renovate/npm-sequelize-vulnerability
branch
from
November 26, 2020 02:01
aa8bfa1 to
05938ea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.39.0->4.44.4GitHub Vulnerability Alerts
CVE-2019-10752
Affected versions of
sequelizeare vulnerable to SQL Injection. The functionsequelize.json()incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query. Exploitation example:const Sequelize = require('sequelize');
const sequelize = new Sequelize({
dialect: 'sqlite',
storage: 'database.sqlite'
});
const TypeError = sequelize.define('TypeError', {
name: Sequelize.STRING,
});
TypeError.sync({force: true}).then(() => {
return TypeError.create({name: "SELECT tbl_name FROM sqlite_master"});
});