Description
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.
Remediation
References
https://github.com/knex/knex/issues/1227
https://nvd.nist.gov/vuln/detail/CVE-2016-20018
https://www.ghostccamm.com/blog/knex_sqli/
Related Vulnerabilities
CVE-2017-3201 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer
CVE-2020-7707 Vulnerability in maven package org.webjars.npm:property-expr
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-solrj
CVE-2020-7627 Vulnerability in npm package node-key-sender
CVE-2021-41165 Vulnerability in maven package org.webjars.npm:ckeditor4