Description
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
Remediation
References
https://csirt.divd.nl/CVE-2022-29823/
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2017-18635 Vulnerability in npm package @novnc/novnc
CVE-2019-15955 Vulnerability in npm package total.js
CVE-2019-14862 Vulnerability in maven package org.webjars.npm:knockout
CVE-2019-10907 Vulnerability in maven package org.airsonic.player:airsonic-main
CVE-2018-16491 Vulnerability in maven package org.webjars.npm:node.extend