Description
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
Remediation
References
https://csirt.divd.nl/CVE-2022-29823/
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2019-20921 Vulnerability in maven package org.webjars.npm:bootstrap-select
CVE-2016-10533 Vulnerability in npm package express-restify-mongoose
CVE-2020-28278 Vulnerability in npm package shvl
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack
CVE-2019-1003088 Vulnerability in maven package egor-n:fabric-beta-publisher