GHSA-f598-mfpv-gmfx
CRITICALCVE-2023-22578Sequelize 6.28.2 and prior has a dangerous feature where using parentheses in the attribute option would make Sequelize use the string as-is in the SQL
- Affected
- < 7.0.0-alpha.20
- Fixed in
- 7.0.0-alpha.20
- Weakness
- CWE-790
- Published
- 2023-02-24
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference