GHSA-4jv9-3563-23j3
HIGHCVE-2016-20018Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. This vulnerability has been fixed in version 2.4.0.
- Affected
- < 2.4.0
- Fixed in
- 2.4.0
- Weakness
- CWE-89
- Published
- 2022-12-19
- Source
- github