Bug 2155858 (CVE-2016-20018) - CVE-2016-20018 Knex: SQL injection
Summary: CVE-2016-20018 Knex: SQL injection
Keywords:
Status: NEW
Alias: CVE-2016-20018
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2154881
TreeView+ depends on / blocked
 
Reported: 2022-12-22 16:14 UTC by Sage McTaggart
Modified: 2023-07-07 08:32 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: ---
Doc Text:
An SQL injection flaw was found in Knex.js. This issue allows someone to ignore the WHERE clause of an SQL query, resulting in impact to confidentiality.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sage McTaggart 2022-12-22 16:14:16 UTC
CVE-2016-20018

Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.

https://www.ghostccamm.com/blog/knex_sqli/
https://github.com/knex/knex/issues/1227


Note You need to log in before you can comment on or make changes to this bug.