github.com
https://github.com/typeorm/typeorm GHSA-W7Q7-VJP8-7JV4
SQL Injection in typeorm
Description
Versions of `typeorm` before 0.1.15 are vulnerable to SQL Injection. Field names are not properly validated allowing attackers to inject SQL statements and execute arbitrary SQL queries. ## Recommendation Upgrade to version 0.1.15
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
typeormBrowse npm / typeorm | GitHub Advisory | Before 0.1.15 · Fixed in 0.1.15 | affected |
References
4github.com
https://github.com/typeorm/typeorm/commit/d46c8b0e6c0db56bb5976a4917e9f67a43715111 hackerone.com
https://hackerone.com/reports/319458 npmjs.com
https://www.npmjs.com/advisories/800