Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency sequelize to v4 [SECURITY] #39

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

cmorell
Copy link
Owner

@cmorell cmorell commented Jun 3, 2020

This PR contains the following updates:

Package Type Update Change
sequelize (source) dependencies major 1.7.8 -> 4.44.3

GitHub Vulnerability Alerts

CVE-2015-1369

SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.

CVE-2016-10553

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.

CVE-2016-10556

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS In Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped. This causes potential SQL injection in sequelize 3.19.3 and earlier, where a malicious user could put ["test", "'); DELETE TestTable WHERE Id = 1 --')"] inside of database.query('SELECT * FROM TestTable WHERE Name IN (:names)', { replacements: { names: directCopyOfUserInput } }); and cause the SQL statement to become SELECT Id FROM Table WHERE Name IN ('test', '\'); DELETE TestTable WHERE Id = 1 --'). In Postgres, MSSQL, and SQLite, the backslash has no special meaning. This causes the the statement to delete whichever Id has a value of 1 in the TestTable table.

CVE-2016-10550

sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the limit or order parameters, a malicious user can put in their own SQL statements. This affects sequelize 3.16.0 and earlier.

GHSA-wfp9-vr4j-f49j / WS-2019-0053

Versions of sequelize prior to 4.12.0 are vulnerable to NoSQL Injection. Query operators such as $gt are not properly sanitized and may allow an attacker to alter data queries, leading to NoSQL Injection.

CVE-2019-10752

Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.

CVE-2019-10748

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

CVE-2019-10749

sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.


Release Notes

sequelize/sequelize

v4.44.3

Compare Source

Security

This release fixes two security issues for MySQL, both affecting same component.

https://snyk.io/vuln/SNYK-JS-SEQUELIZE-450221

v4.44.2

Compare Source

Bug Fixes
  • use files and remove .npmignore (6674a3c)

v4.44.1

Compare Source

Bug Fixes

v4.44.0

Compare Source

Bug Fixes
Features
  • postgres: enable standard conforming strings when required (#​10746) (c9d3a97)

v4.43.2

Compare Source

Bug Fixes

v4.43.1

Compare Source

v4.43.0

Compare Source

v4.42.1

Compare Source

v4.42.0

Compare Source

v4.41.2

Compare Source

v4.41.1

Compare Source

v4.41.0

Compare Source

v4.40.0

Compare Source

v4.39.1

Compare Source

v4.39.0

Compare Source

v4.38.1

Compare Source

v4.38.0

Compare Source

v4.37.10

Compare Source

v4.37.9

Compare Source

v4.37.8

Compare Source

v4.37.7

Compare Source

v4.37.6

Compare Source

v4.37.5

Compare Source

v4.37.4

Compare Source

v4.37.3

Compare Source

v4.37.2

Compare Source

v4.37.1

Compare Source

v4.37.0

Compare Source

v4.36.1

Compare Source

v4.36.0

Compare Source

v4.35.5

Compare Source

v4.35.4

Compare Source

v4.35.3

Compare Source

v4.35.2

Compare Source

v4.35.1

Compare Source

v4.35.0

Compare Source

v4.34.1

Compare Source

v4.34.0

Compare Source

v4.33.4

Compare Source

v4.33.3

Compare Source

v4.33.2

Compare Source

v4.33.1

Compare Source

v4.33.0

Compare Source

v4.32.7

Compare Source

v4.32.6

Compare Source

v4.32.5

Compare Source

v4.32.4

Compare Source

v4.32.3

Compare Source

v4.32.2

Compare Source

v4.32.1

Compare Source

v4.32.0

Compare Source

v4.31.2

Compare Source

v4.31.1

Compare Source

v4.31.0

Compare Source

v4.30.2

Compare Source

v4.30.1

Compare Source

v4.30.0

Compare Source

v4.29.3

Compare Source

v4.29.2

Compare Source

v4.29.1

Compare Source

v4.29.0

Compare Source

v4.28.8

Compare Source

v4.28.7

Compare Source

v4.28.6

Compare Source

v4.28.5

Compare Source

v4.28.4

Compare Source

v4.28.3

Compare Source

v4.28.2

Compare Source

v4.28.1

Compare Source

v4.28.0

Compare Source

v4.27.0

Compare Source

v4.26.0

Compare Source

v4.25.2

Compare Source

v4.25.1

Compare Source

v4.25.0

Compare Source

v4.24.0

Compare Source

v4.23.4

Compare Source

v4.23.3

Compare Source

v4.23.2

Compare Source

v4.23.1

Compare Source

v4.23.0

Compare Source

v4.22.16

Compare Source

v4.22.15

Compare Source

v4.22.14

Compare Source

v4.22.13

Compare Source

v4.22.12

Compare Source

v4.22.11

Compare Source

v4.22.10

Compare Source

v4.22.9

Compare Source

v4.22.8

Compare Source

v4.22.7

Compare Source

v4.22.6

Compare Source

v4.22.5

Compare Source

v4.22.4

Compare Source

v4.22.3

Compare Source

v4.22.2

Compare Source

v4.22.1

Compare Source

v4.22.0

Compare Source

v4.21.0

Compare Source

v4.20.3

Compare Source

v4.20.2

Compare Source

v4.20.1

Compare Source

v4.20.0

Compare Source

v4.19.0

Compare Source

v4.18.0

Compare Source

v4.17.2

Compare Source

v4.17.1

Compare Source

v4.17.0

Compare Source

v4.16.2

Compare Source

v4.16.1

Compare Source

v4.16.0

Compare Source

v4.15.2

Compare Source

v4.15.1

Compare Source

v4.15.0

Compare Source

v4.14.0

Compare Source

v4.13.17

Compare Source

v4.13.16

Compare Source

v4.13.15

Compare Source

v4.13.14

Compare Source

v4.13.13

Compare Source

v4.13.12

Compare Source

v4.13.11

Compare Source

v4.13.10

Compare Source

v4.13.9

Compare Source

v4.13.8

Compare Source

v4.13.7

Compare Source

v4.13.6

Compare Source

v4.13.5

Compare Source

v4.13.4

Compare Source

v4.13.3

Compare Source

v4.13.2

Compare Source

v4.13.1

Compare Source

v4.13.0

Compare Source

v4.12.0

Compare Source

v4.11.7

Compare Source

v4.11.6

Compare Source

v4.11.5

Compare Source

v4.11.4

Compare Source

v4.11.3

Compare Source

v4.11.2

Compare Source

v4.11.1

Compare Source

v4.11.0

Compare Source

v4.10.3

Compare Source

v4.10.2

Compare Source

v4.10.1

Compare Source

v4.10.0

Compare Source

v4.9.0

Compare Source

v4.8.4

Compare Source

v4.8.3

Compare Source

v4.8.2

Compare Source

v4.8.1

Compare Source

v4.8.0

Compare Source

v4.7.5

Compare Source

v4.7.4

Compare Source

v4.7.3

Compare Source

v4.7.2

Compare Source

v4.7.1

Compare Source

v4.7.0

Compare Source

v4.6.0

Compare Source

v4.5.0

Compare Source

v4.4.10

Compare Source

v4.4.9

Compare Source

v4.4.8

Compare Source

v4.4.7

Compare Source

v4.4.6

Compare Source

v4.4.5

Compare Source

v4.4.4

Compare Source

v4.4.3

Compare Source

v4.4.2

Compare Source

v4.4.1

Compare Source

v4.4.0

Compare Source

v4.3.2

Compare Source

v4.3.1

Compare Source

v4.3.0

Compare Source

v4.2.1

Compare Source

v4.2.0

Compare Source

v4.1.0

Compare Source

v4.0.0

Compare Source

v3.35.1

Compare Source

v3.35.0

Compare Source

v3.34.0

Compare Source

v3.33.0

Compare Source

v3.32.1

Compare Source

v3.31.2

Compare Source

v3.31.1

Compare Source

v3.31.0

Compare Source

v3.30.4

Compare Source

v3.30.3

Compare Source

v3.30.2

Compare Source

v3.30.1

Compare Source

v3.30.0

Compare Source

v3.29.0

Compare Source

v3.28.0

Compare Source

v3.27.0

Compare Source

v3.26.0

Compare Source

v3.25.1

Compare Source

v3.25.0

Compare Source

v3.24.8

Compare Source

v3.24.7

Compare Source

v3.24.6

Compare Source

v3.24.5

Compare Source

v3.24.4

Compare Source

v3.24.3

Compare Source

v3.24.2

Compare Source

v3.24.1

Compare Source

v3.24.0

Compare Source

v3.23.6

Compare Source

v3.23.5

Compare Source

v3.23.4

Compare Source

v3.23.3

Compare Source

v3.23.2

Compare Source

v3.23.1

Compare Source

v3.23.0

Compare Source

v3.22.0

Compare Source

v3.21.0

Compare Source

v3.20.0

Compare Source

v3.19.3

Compare Source

v3.19.2

Compare Source

v3.19.1

Compare Source

v3.19.0

Compare Source

v3.18.0

Compare Source

v3.17.3

Compare Source

v3.17.2

Compare Source

v3.17.1

Compare Source

v3.17.0

Compare Source

v3.16.0

Compare Source

v3.15.1

Compare Source

v3.15.0

Compare Source

v3.14.2

Compare Source

v3.14.1

Compare Source

v3.14.0

Compare Source

v3.13.0

Compare Source

v3.12.2

Compare Source

v3.12.1

Compare Source

v3.12.0

Compare Source

v3.11.0

Compare Source

v3.10.0

Compare Source

v3.9.0

Compare Source

v3.8.0

Compare Source

v3.7.1

Compare Source

v3.7.0

Compare Source

v3.6.0

Compare Source

v3.5.1

Compare Source

v3.5.0

Compare Source

v3.4.1

Compare Source

v3.4.0

Compare Source

v3.3.2

Compare Source

v3.3.1

Compare Source

v3.3.0

Compare Source

v3.2.0

Compare Source

v3.1.1

Compare Source

v3.1.0

Compare Source

v3.0.1

Compare Source

v3.0.0

Compare Source

v2.1.3

Compare Source

v2.1.2

Compare Source

v2.1.1

Compare Source

v2.1.0

Compare Source

v2.0.6

Compare Source

v2.0.5

Compare Source

v2.0.4

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source

v2.0.1

Compare Source

v2.0.0

Compare Source

v1.7.11

Compare Source

v1.7.10

Compare Source

v1.7.9

Compare Source


Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants