CVE-2023-22580

MEDIUM5.3EPSS 0.29%

Sequelize information disclosure vulnerability

Published: 2/16/2023Modified: 11/8/2023
Also known as:GHSA-8c25-f3mj-v6h8

Description

Due to improper input filtering in the sequelize js library, can malicious queries lead to sensitive information disclosure.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (8)