Junglewise Threat Intelligence

CVE-2023-22579: Sequelize unsafe fall-through in getWhereConditions

CVE-2023-22579 · Severity: low · CVSS 3.1 · Published 2023-02-23

Technologies: Sequelize @Sequelize/Core, sequelize (npm). Vendors: npm.

Executive brief

Sequelize, a popular Node.js library for interacting with databases, contains a type-validation flaw that allows invalid query parameters to pass silently instead of being rejected. An attacker with database access could craft malicious queries that bypass input validation, potentially leading to unauthorized data access, modification, or system availability issues depending on how the application uses the library.

Technical details

The vulnerability is a type-confusion issue (CWE-843) in the getWhereConditions function of Sequelize. When an invalid (non-object) value is passed to the `where` option of a query, the code fails to throw an error and instead silently ignores the invalid input. This occurs only at the top level of the where clause. An authenticated attacker can exploit this by providing type-mismatched values (e.g., a Date object where an object is expected) to manipulate query behavior. The patches are available in sequelize@6.28.1 and @sequelize/core@7.0.0-alpha.20.

Affected products

  • Sequelize sequelize before 6.28.1
  • Sequelize @sequelize/core before 7.0.0-alpha.20

Timeline

  • 2023-02-23: disclosed: Vulnerability published in GHSA
  • 2023-02-23: patched: Patches released: sequelize@6.28.1 and @sequelize/core@7.0.0-alpha.20

References

Related threats