OSV 1.4.0 · github-reviewed · 修改于 2021-08-19 05:50
发布时间
2019-10-22 00:12
GitHub 审查时间
2019-10-18 01:36
NVD 发布时间
2019-10-09 04:15
源文件
advisories/github-reviewed/2019/10/GHSA-58v4-qwx5-7f59/GHSA-58v4-qwx5-7f59.json
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.