Description
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
Remediation
References
https://csirt.divd.nl/CVE-2022-29823/
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oidc
CVE-2021-23346 Vulnerability in maven package org.webjars.npm:html-parse-stringify2
CVE-2020-13410 Vulnerability in npm package aedes
CVE-2019-14900 Vulnerability in maven package org.hibernate:hibernate-core
CVE-2020-7792 Vulnerability in maven package org.webjars.npm:mout