7.5
CVE-2023-22580
- EPSS 0.58%
- Veröffentlicht 16.02.2023 15:15:18
- Zuletzt bearbeitet 21.11.2024 07:45:00
- Quelle csirt@divd.nl
- CVE-Watchlists
- Unerledigt
Sequalize - Bad query filtering leading to SQL errors
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sequelizejs ≫ Sequelize SwPlatformnode.js Version < 6.28.1
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha1 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha10 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha11 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha12 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha13 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha14 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha15 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha16 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha17 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha18 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha19 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha2 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha2.1 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha2.2 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha3 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha4 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha5 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha6 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha7 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha8 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updatealpha9 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updateoc_test_1 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updateoc_test_2 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updateoc_test_3 SwPlatformnode.js
Sequelizejs ≫ Sequelize Version7.0.0 Updateoc_test_4 SwPlatformnode.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.432 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| csirt@divd.nl | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://csirt.divd.nl/DIVD-2022-00020/
https://csirt.divd.nl/CVE-2023-22580