SQL Injection in waterline-sequel
High severity
GitHub Reviewed
Published
Feb 18, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Feb 18, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Affected versions of
waterline-sequel
are vulnerable to SQL injection in cases where user input is passed into thelike
,contains
,startsWith
, orendsWith
methods.Recommendation
Upgrade to at least version 0.5.1
References