CVE-2019-10748: SQL Injection
Published Oct 28, 2019
·Updated
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
Affected Software
3 affected components
Sequelizejs Sequelize Node.js>=3.0.0<3.35.1
Sequelizejs Sequelize Node.js>=4.0.0<4.44.3
Sequelizejs Sequelize Node.js>=5.0.0<=5.8.11
Remediation
Patch Available
Event History
Oct 28, 2019
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-10748.
2
What is the severity of CVE-2019-10748?
The severity of CVE-2019-10748 is critical with a score of 9.8.
3
What software versions are affected by CVE-2019-10748?
Sequelize versions prior to 3.35.1, 4.44.3, and 5.8.11 are affected by CVE-2019-10748.
4
What is the vulnerability description of CVE-2019-10748?
CVE-2019-10748 is a vulnerability in Sequelize where JSON path keys are not properly escaped for the MySQL/MariaDB dialects, leading to SQL Injection.
5
How can I fix CVE-2019-10748?
To fix CVE-2019-10748, update to Sequelize versions 3.35.1, 4.44.3, or 5.8.11 or later.