Junglewise Threat Intelligence

CVE-2015-1369: Sequelize SQL injection in order parameter

CVE-2015-1369 · Severity: info · CVSS 7.5 · Published 2017-10-24

Technologies: Sequelize. Vendors: npm.

Executive brief

Sequelize is a popular Node.js ORM library used to manage database interactions in web applications. A SQL injection vulnerability in versions 2.0.0-rc7 and earlier allows attackers to inject arbitrary SQL commands through the order parameter, potentially enabling data theft, modification, or deletion of database records when user input is passed directly to query ordering functions.

Technical details

This vulnerability is a SQL injection flaw in Sequelize's query builder that occurs when unsanitized user input is passed into the order parameter of finder methods such as findAndCountAll(). The root cause is insufficient input validation on the sort direction values. An attacker can craft malicious input (e.g., 'DESC; delete from test;') in the order array to inject arbitrary SQL commands. The vulnerability requires the attacker to control the order parameter value, typically through API parameters or user-controlled input in a web application. Successful exploitation allows arbitrary SQL execution with the database user's privileges. The vulnerability was fixed in version 2.0.0-rc8 and later.

Affected products

  • Sequelize Sequelize 2.0.0-rc7 and earlier

Timeline

  • 2015-01-12: disclosed: SQL injection vulnerability reported in GitHub issue #2906
  • 2015-01-23: patched: Fixed in version 2.0.0-rc8

References

Related threats