Description
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0687 | knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB. |
Github GHSA |
GHSA-58v4-qwx5-7f59 | SQL Injection in knex |
References
| Link | Providers |
|---|---|
| https://snyk.io/vuln/SNYK-JS-KNEX-471962 |
|
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.495Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10757
No data.
Status : Modified
Published: 2019-10-08T20:15:11.730
Modified: 2024-11-21T04:19:51.753
Link: CVE-2019-10757
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA