Description
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Remediation
References
https://snyk.io/vuln/SNYK-JS-KNEX-471962
Related Vulnerabilities
CVE-2020-7788 Vulnerability in maven package org.webjars.bowergithub.npm:ini
CVE-2022-0401 Vulnerability in npm package w-zip
CVE-2023-29003 Vulnerability in npm package @sveltejs/kit
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee10:jetty-ee10-servlets
CVE-2022-36903 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector