CVE-2023-22580: Sequalize - Bad query filtering leading to SQL errors
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22580?
CVE-2023-22580 is a vulnerability in the Sequelize.js library that allows for sensitive information disclosure due to improper input filtering.
How severe is CVE-2023-22580?
CVE-2023-22580 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2023-22580?
The affected software versions include Sequelize.js 6.28.1 and Sequelize.js 7.0.0-alpha1 to 7.0.0-oc_test_4 in Node.js.
How can malicious queries lead to sensitive information disclosure in Sequelize.js?
Malicious queries can lead to sensitive information disclosure in Sequelize.js due to the improper input filtering, allowing attackers to manipulate the database queries and access sensitive data.
Where can I find more information about CVE-2023-22580?
You can find more information about CVE-2023-22580 at the following links: [Link 1](https://csirt.divd.nl/CVE-2023-22580), [Link 2](https://csirt.divd.nl/DIVD-2022-00020/)