Skip to content

Conversation

@BrenoMazieiro
Copy link

@BrenoMazieiro BrenoMazieiro commented Apr 24, 2021

Some dependencies has security problems and should be updated.

CVE-2019-10757
high severity
Vulnerable versions: < 0.19.5
Patched version: 0.19.5
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.

@ev-rvs
Copy link

ev-rvs commented May 11, 2022

Is there an ETA on merging this patched fix? There is a severe vulnerability that requires dependent package versions to be updated within this package - thanks @BrenoMazieiro for submitting this pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants