Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in node-sql #395

Open
bteng22 opened this issue May 14, 2018 · 2 comments
Open

Security vulnerability in node-sql #395

bteng22 opened this issue May 14, 2018 · 2 comments

Comments

@bteng22
Copy link

bteng22 commented May 14, 2018

Medium severity vulnerability found on [email protected] according to Snyk:
https://snyk.io/vuln/npm:sql:20180512

The report:
https://hackerone.com/reports/319465

@spion-h4
Copy link

If anyone is interested, we made a patch at https://github.com/TokyoFarmer/node-sql-2

It works with postgresql, but we've not tested if all other databases will behave correctly.

@danielmcq
Copy link

This is being reported when running npm audit now as well. They list it at https://nodesecurity.io/advisories/662.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants