CVE-2020-8158: SQL Injection
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited remotely over the network with low attack complexity, without authentication or user interaction. The provided data does not identify a specific exposed application endpoint or configuration.
What impact can prototype pollution have in an affected application?
An attacker may add or modify Object properties. The reported downstream impacts include denial of service and SQL injection, with high potential impact to confidentiality, integrity, and availability.
Which TypeORM versions are affected?
TypeORM versions earlier than 0.2.25 are affected. A patch is available; upgrade to a patched version rather than remaining on a version below 0.2.25.