CVE-2019-10748

Source
https://cve.org/CVERecord?id=CVE-2019-10748
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10748.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-10748
Aliases
Related
  • SNYK-JS-SEQUELIZE-450221
Published
2019-10-29T19:15:16.687Z
Modified
2026-03-12T22:59:14.365907Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.

References

Affected packages

Git / github.com/sequelize/sequelize

Affected ranges

Type
GIT
Repo
https://github.com/sequelize/sequelize
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.35.1"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.44.3"
        }
    ]
}

Affected versions

3.*
3.12.1
3.22.0
3.23.0
v3.*
v3.0.0
v3.0.1
v3.1.0
v3.1.1
v3.10.0
v3.12.0
v3.12.2
v3.13.0
v3.14.0
v3.14.2
v3.15.0
v3.15.1
v3.16.0
v3.17.0
v3.17.1
v3.17.2
v3.17.3
v3.18.0
v3.19.0
v3.19.1
v3.19.2
v3.19.3
v3.2.0
v3.20.0
v3.21.0
v3.23.0
v3.23.1
v3.23.2
v3.23.3
v3.23.4
v3.23.5
v3.23.6
v3.24.0
v3.24.1
v3.24.2
v3.24.3
v3.24.4
v3.24.5
v3.24.7
v3.25.0
v3.25.1
v3.26.0
v3.27.0
v3.28.0
v3.29.0
v3.3.0
v3.3.1
v3.3.2
v3.30.0
v3.30.1
v3.30.2
v3.30.3
v3.30.4
v3.31.0
v3.31.1
v3.31.2
v3.32.0
v3.32.1
v3.33.0
v3.35.0
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.6.0
v3.7.0
v3.7.1
v3.8.0
v3.9.0
v4.*
v4.0.0
v4.0.0-0
v4.0.0-1
v4.0.0-2
v4.1.0
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.11.0
v4.11.1
v4.11.2
v4.11.3
v4.11.4
v4.11.5
v4.11.6
v4.11.7
v4.12.0
v4.13.0
v4.13.1
v4.13.10
v4.13.11
v4.13.12
v4.13.13
v4.13.14
v4.13.15
v4.13.16
v4.13.17
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.13.7
v4.13.8
v4.13.9
v4.14.0
v4.15.0
v4.15.1
v4.15.2
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.17.1
v4.17.2
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.21.0
v4.22.0
v4.22.1
v4.22.10
v4.22.11
v4.22.12
v4.22.13
v4.22.14
v4.22.15
v4.22.16
v4.22.2
v4.22.3
v4.22.4
v4.22.5
v4.22.6
v4.22.7
v4.22.8
v4.22.9
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.23.4
v4.24.0
v4.25.0
v4.25.1
v4.25.2
v4.26.0
v4.27.0
v4.28.0
v4.28.1
v4.28.2
v4.28.3
v4.28.4
v4.28.5
v4.28.6
v4.28.7
v4.28.8
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.3.0
v4.3.1
v4.3.2
v4.30.0
v4.30.1
v4.30.2
v4.31.0
v4.31.1
v4.31.2
v4.32.0
v4.32.1
v4.32.2
v4.32.3
v4.32.4
v4.32.5
v4.32.6
v4.32.7
v4.33.0
v4.33.1
v4.33.2
v4.33.3
v4.33.4
v4.34.0
v4.34.1
v4.35.0
v4.35.1
v4.35.2
v4.35.3
v4.35.4
v4.35.5
v4.36.0
v4.36.1
v4.37.0
v4.37.1
v4.37.10
v4.37.2
v4.37.3
v4.37.4
v4.37.5
v4.37.6
v4.37.7
v4.37.8
v4.37.9
v4.38.0
v4.38.1
v4.39.0
v4.39.1
v4.4.0
v4.4.1
v4.4.10
v4.4.2
v4.4.4
v4.4.5
v4.4.6
v4.4.7
v4.4.8
v4.4.9
v4.40.0
v4.41.0
v4.41.1
v4.41.2
v4.42.0
v4.42.1
v4.43.0
v4.43.1
v4.43.2
v4.44.0
v4.44.1
v4.44.2
v4.5.0
v4.6.0
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.8.0
v4.8.1
v4.8.2
v4.8.3
v4.8.4
v4.9.0

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "5.0.0"
            },
            {
                "last_affected": "5.8.11"
            }
        ]
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10748.json"