Description
connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
Remediation
References
https://github.com/voxpelli/node-connect-pg-simple/security/advisories/GHSA-xqh8-5j36-4556
Related Vulnerabilities
CVE-2020-9488 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2020-7691 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2020-19697 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2022-23223 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2022-4348 Vulnerability in maven package com.ruoyi:ruoyi-common