CVE-2023-22580: Sequelize information disclosure vulnerability
(updated )
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
References
- csirt.divd.nl/CVE-2023-22580
- csirt.divd.nl/DIVD-2022-00020/
- github.com/advisories/GHSA-8c25-f3mj-v6h8
- github.com/sequelize/sequelize/pull/15375
- github.com/sequelize/sequelize/pull/15699
- github.com/sequelize/sequelize/releases/tag/v6.28.1
- github.com/sequelize/sequelize/releases/tag/v7.0.0-alpha.20
- nvd.nist.gov/vuln/detail/CVE-2023-22580
Detect and mitigate CVE-2023-22580 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →