Description
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
Remediation
References
https://csirt.divd.nl/CVE-2022-29823/
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2023-37950 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2022-1274 Vulnerability in maven package org.keycloak:keycloak-themes
CVE-2022-43411 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2017-7669 Vulnerability in maven package org.apache.hadoop:hadoop-common