CVE-2023-22579: Unsafe fall-through in getWhereConditions
(updated )
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
References
- csirt.divd.nl/CVE-2023-22579
- csirt.divd.nl/DIVD-2022-00020/
- github.com/advisories/GHSA-vqfx-gj96-3w95
- github.com/sequelize/sequelize/discussions/15698
- github.com/sequelize/sequelize/pull/15375
- github.com/sequelize/sequelize/pull/15699
- github.com/sequelize/sequelize/releases/tag/v6.28.1
- github.com/sequelize/sequelize/releases/tag/v7.0.0-alpha.20
- github.com/sequelize/sequelize/security/advisories/GHSA-vqfx-gj96-3w95
- nvd.nist.gov/vuln/detail/CVE-2023-22579
Detect and mitigate CVE-2023-22579 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →