Description
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Remediation
References
https://snyk.io/vuln/SNYK-JS-KNEX-471962
Related Vulnerabilities
CVE-2023-38889 Vulnerability in maven package org.alluxio:alluxio-core
CVE-2022-39322 Vulnerability in npm package @keystone-6/core
CVE-2022-43411 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2017-16092 Vulnerability in npm package sencisho
CVE-2012-4534 Vulnerability in maven package org.apache.tomcat:tomcat-coyote