Description
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
Remediation
References
https://csirt.divd.nl/CVE-2022-2422
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2017-16114 Vulnerability in maven package org.webjars:marked
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-25640 Vulnerability in maven package org.jboss.genericjms:generic-jms-ra-jar