9.9

CVE-2023-22579

Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SequelizejsSequelize SwPlatformnode.js Version < 6.28.1
SequelizejsSequelize Version7.0.0 Updatealpha1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha10 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha11 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha12 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha13 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha14 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha15 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha16 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha17 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha18 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha19 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2.1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha2.2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha3 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha4 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha5 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha6 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha7 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha8 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updatealpha9 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_1 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_2 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_3 SwPlatformnode.js
SequelizejsSequelize Version7.0.0 Updateoc_test_4 SwPlatformnode.js
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.614
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
csirt@divd.nl 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.