TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Sequelize ORM NPM library found vulnerable to SQL Injection attacks

1 点作者 lirantal超过 5 年前

1 comment

lirantal超过 5 年前
kudos to Kirill from the security research team who worked on this discovery as well as providing the fixes (!) and many thanks and appreciation to the Sequelize project maintainers who worked with us on the responsible disclosure and promptly issued fixes to vulnerable versions where necessary.<p>Sequelize is a pretty popular ORM for Node.js projects so you should probably test your project with snyk and ensure you aren&#x27;t vulnerable (npm audit is still lagging behind on this vulnerability for 24 days currently).