Executive brief
knex is a popular query builder library used by developers to safely construct database queries for PostgreSQL, MySQL, and SQLite3. A flaw in the MSSQL dialect allows attackers to inject arbitrary SQL commands by crafting specially malformed identifiers, potentially allowing them to steal, modify, or delete database contents. The vulnerability requires network access to an application using the affected library but does not require authentication or user interaction.
Technical details
This is a SQL Injection vulnerability (CWE-89) in knex.js versions prior to 0.19.5, specifically affecting the MSSQL dialect implementation. The root cause is incorrect escaping of database identifiers, which allows an attacker to break out of the intended identifier context and inject arbitrary SQL. The attack is remotely exploitable over the network, requires no authentication or privileges, and does not require user interaction—an attacker can directly send malicious input through an application using the vulnerable library. Successful exploitation allows complete compromise of the database: attackers can read sensitive data, modify records, delete data, or execute administrative commands depending on database permissions. The fix is to upgrade to knex version 0.19.5 or later.
Affected products
- knex knex < 0.19.5
Timeline
- 2019-10-07: disclosed
- 2019-10-21: advisory
- 2019-10-08: patched: Fix released in version 0.19.5