CVE-2016-10554 Information
Feb 14, 2021
cve
Description
sequelize is an Object-relational mapping or a middleman to convert things from Postgres MySQL MariaDB SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3 sequelize defaulted SQLite to use MySQL backslash escaping even though SQLite uses Postgres escaping.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/sequelize/sequelize/commit/c876192aa6ce1f67e22b26a4d175b8478615f42d https://nodesecurity.io/advisories/113
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: