Description
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Remediation
References
https://snyk.io/vuln/SNYK-JS-KNEX-471962
Related Vulnerabilities
CVE-2020-36181 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2018-12532 Vulnerability in maven package org.richfaces:richfaces-a4j
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2020-7649 Vulnerability in npm package snyk-broker
CVE-2018-3739 Vulnerability in npm package https-proxy-agent