Update dependency sequelize to v4 [SECURITY] #39
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.7.8
->4.44.3
GitHub Vulnerability Alerts
CVE-2015-1369
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.
CVE-2016-10553
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.
CVE-2016-10556
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped. This causes potential SQL injection in sequelize 3.19.3 and earlier, where a malicious user could put
["test", "'); DELETE TestTable WHERE Id = 1 --')"]
inside ofdatabase.query('SELECT * FROM TestTable WHERE Name IN (:names)', { replacements: { names: directCopyOfUserInput } });
and cause the SQL statement to becomeSELECT Id FROM Table WHERE Name IN ('test', '\'); DELETE TestTable WHERE Id = 1 --')
. In Postgres, MSSQL, and SQLite, the backslash has no special meaning. This causes the the statement to delete whichever Id has a value of 1 in the TestTable table.CVE-2016-10550
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the
limit
ororder
parameters, a malicious user can put in their own SQL statements. This affects sequelize 3.16.0 and earlier.GHSA-wfp9-vr4j-f49j / WS-2019-0053
Versions of sequelize prior to 4.12.0 are vulnerable to NoSQL Injection. Query operators such as $gt are not properly sanitized and may allow an attacker to alter data queries, leading to NoSQL Injection.
CVE-2019-10752
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
CVE-2019-10748
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
CVE-2019-10749
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
Release Notes
sequelize/sequelize
v4.44.3
Compare Source
Security
This release fixes two security issues for MySQL, both affecting same component.
https://snyk.io/vuln/SNYK-JS-SEQUELIZE-450221
v4.44.2
Compare Source
Bug Fixes
v4.44.1
Compare Source
Bug Fixes
v4.44.0
Compare Source
Bug Fixes
Features
v4.43.2
Compare Source
Bug Fixes
v4.43.1
Compare Source
v4.43.0
Compare Source
v4.42.1
Compare Source
v4.42.0
Compare Source
v4.41.2
Compare Source
v4.41.1
Compare Source
v4.41.0
Compare Source
v4.40.0
Compare Source
v4.39.1
Compare Source
v4.39.0
Compare Source
v4.38.1
Compare Source
v4.38.0
Compare Source
v4.37.10
Compare Source
v4.37.9
Compare Source
v4.37.8
Compare Source
v4.37.7
Compare Source
v4.37.6
Compare Source
v4.37.5
Compare Source
v4.37.4
Compare Source
v4.37.3
Compare Source
v4.37.2
Compare Source
v4.37.1
Compare Source
v4.37.0
Compare Source
v4.36.1
Compare Source
v4.36.0
Compare Source
v4.35.5
Compare Source
v4.35.4
Compare Source
v4.35.3
Compare Source
v4.35.2
Compare Source
v4.35.1
Compare Source
v4.35.0
Compare Source
v4.34.1
Compare Source
v4.34.0
Compare Source
v4.33.4
Compare Source
v4.33.3
Compare Source
v4.33.2
Compare Source
v4.33.1
Compare Source
v4.33.0
Compare Source
v4.32.7
Compare Source
v4.32.6
Compare Source
v4.32.5
Compare Source
v4.32.4
Compare Source
v4.32.3
Compare Source
v4.32.2
Compare Source
v4.32.1
Compare Source
v4.32.0
Compare Source
v4.31.2
Compare Source
v4.31.1
Compare Source
v4.31.0
Compare Source
v4.30.2
Compare Source
v4.30.1
Compare Source
v4.30.0
Compare Source
v4.29.3
Compare Source
v4.29.2
Compare Source
v4.29.1
Compare Source
v4.29.0
Compare Source
v4.28.8
Compare Source
v4.28.7
Compare Source
v4.28.6
Compare Source
v4.28.5
Compare Source
v4.28.4
Compare Source
v4.28.3
Compare Source
v4.28.2
Compare Source
v4.28.1
Compare Source
v4.28.0
Compare Source
v4.27.0
Compare Source
v4.26.0
Compare Source
v4.25.2
Compare Source
v4.25.1
Compare Source
v4.25.0
Compare Source
v4.24.0
Compare Source
v4.23.4
Compare Source
v4.23.3
Compare Source
v4.23.2
Compare Source
v4.23.1
Compare Source
v4.23.0
Compare Source
v4.22.16
Compare Source
v4.22.15
Compare Source
v4.22.14
Compare Source
v4.22.13
Compare Source
v4.22.12
Compare Source
v4.22.11
Compare Source
v4.22.10
Compare Source
v4.22.9
Compare Source
v4.22.8
Compare Source
v4.22.7
Compare Source
v4.22.6
Compare Source
v4.22.5
Compare Source
v4.22.4
Compare Source
v4.22.3
Compare Source
v4.22.2
Compare Source
v4.22.1
Compare Source
v4.22.0
Compare Source
v4.21.0
Compare Source
v4.20.3
Compare Source
v4.20.2
Compare Source
v4.20.1
Compare Source
v4.20.0
Compare Source
v4.19.0
Compare Source
v4.18.0
Compare Source
v4.17.2
Compare Source
v4.17.1
Compare Source
v4.17.0
Compare Source
v4.16.2
Compare Source
v4.16.1
Compare Source
v4.16.0
Compare Source
v4.15.2
Compare Source
v4.15.1
Compare Source
v4.15.0
Compare Source
v4.14.0
Compare Source
v4.13.17
Compare Source
v4.13.16
Compare Source
v4.13.15
Compare Source
v4.13.14
Compare Source
v4.13.13
Compare Source
v4.13.12
Compare Source
v4.13.11
Compare Source
v4.13.10
Compare Source
v4.13.9
Compare Source
v4.13.8
Compare Source
v4.13.7
Compare Source
v4.13.6
Compare Source
v4.13.5
Compare Source
v4.13.4
Compare Source
v4.13.3
Compare Source
v4.13.2
Compare Source
v4.13.1
Compare Source
v4.13.0
Compare Source
v4.12.0
Compare Source
v4.11.7
Compare Source
v4.11.6
Compare Source
v4.11.5
Compare Source
v4.11.4
Compare Source
v4.11.3
Compare Source
v4.11.2
Compare Source
v4.11.1
Compare Source
v4.11.0
Compare Source
v4.10.3
Compare Source
v4.10.2
Compare Source
v4.10.1
Compare Source
v4.10.0
Compare Source
v4.9.0
Compare Source
v4.8.4
Compare Source
v4.8.3
Compare Source
v4.8.2
Compare Source
v4.8.1
Compare Source
v4.8.0
Compare Source
v4.7.5
Compare Source
v4.7.4
Compare Source
v4.7.3
Compare Source
v4.7.2
Compare Source
v4.7.1
Compare Source
v4.7.0
Compare Source
v4.6.0
Compare Source
v4.5.0
Compare Source
v4.4.10
Compare Source
v4.4.9
Compare Source
v4.4.8
Compare Source
v4.4.7
Compare Source
v4.4.6
Compare Source
v4.4.5
Compare Source
v4.4.4
Compare Source
v4.4.3
Compare Source
v4.4.2
Compare Source
v4.4.1
Compare Source
v4.4.0
Compare Source
v4.3.2
Compare Source
v4.3.1
Compare Source
v4.3.0
Compare Source
v4.2.1
Compare Source
v4.2.0
Compare Source
v4.1.0
Compare Source
v4.0.0
Compare Source
v3.35.1
Compare Source
v3.35.0
Compare Source
v3.34.0
Compare Source
v3.33.0
Compare Source
v3.32.1
Compare Source
v3.31.2
Compare Source
v3.31.1
Compare Source
v3.31.0
Compare Source
v3.30.4
Compare Source
v3.30.3
Compare Source
v3.30.2
Compare Source
v3.30.1
Compare Source
v3.30.0
Compare Source
v3.29.0
Compare Source
v3.28.0
Compare Source
v3.27.0
Compare Source
v3.26.0
Compare Source
v3.25.1
Compare Source
v3.25.0
Compare Source
v3.24.8
Compare Source
v3.24.7
Compare Source
v3.24.6
Compare Source
v3.24.5
Compare Source
v3.24.4
Compare Source
v3.24.3
Compare Source
v3.24.2
Compare Source
v3.24.1
Compare Source
v3.24.0
Compare Source
v3.23.6
Compare Source
v3.23.5
Compare Source
v3.23.4
Compare Source
v3.23.3
Compare Source
v3.23.2
Compare Source
v3.23.1
Compare Source
v3.23.0
Compare Source
v3.22.0
Compare Source
v3.21.0
Compare Source
v3.20.0
Compare Source
v3.19.3
Compare Source
v3.19.2
Compare Source
v3.19.1
Compare Source
v3.19.0
Compare Source
v3.18.0
Compare Source
v3.17.3
Compare Source
v3.17.2
Compare Source
v3.17.1
Compare Source
v3.17.0
Compare Source
v3.16.0
Compare Source
v3.15.1
Compare Source
v3.15.0
Compare Source
v3.14.2
Compare Source
v3.14.1
Compare Source
v3.14.0
Compare Source
v3.13.0
Compare Source
v3.12.2
Compare Source
v3.12.1
Compare Source
v3.12.0
Compare Source
v3.11.0
Compare Source
v3.10.0
Compare Source
v3.9.0
Compare Source
v3.8.0
Compare Source
v3.7.1
Compare Source
v3.7.0
Compare Source
v3.6.0
Compare Source
v3.5.1
Compare Source
v3.5.0
Compare Source
v3.4.1
Compare Source
v3.4.0
Compare Source
v3.3.2
Compare Source
v3.3.1
Compare Source
v3.3.0
Compare Source
v3.2.0
Compare Source
v3.1.1
Compare Source
v3.1.0
Compare Source
v3.0.1
Compare Source
v3.0.0
Compare Source
v2.1.3
Compare Source
v2.1.2
Compare Source
v2.1.1
Compare Source
v2.1.0
Compare Source
v2.0.6
Compare Source
v2.0.5
Compare Source
v2.0.4
Compare Source
v2.0.3
Compare Source
v2.0.2
Compare Source
v2.0.1
Compare Source
v2.0.0
Compare Source
v1.7.11
Compare Source
v1.7.10
Compare Source
v1.7.9
Compare Source
Renovate configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.