CVE-2022-29822

Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
References
Link Resource
https://csirt.divd.nl/CVE-2022-29822/ Third Party Advisory
https://csirt.divd.nl/DIVD-2022-00020 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:feathersjs:feathers-sequelize:*:*:*:*:*:node.js:*:*

History

02 Jan 2024, 19:15

Type Values Removed Values Added
Summary (en) Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection (en) Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection

07 Nov 2023, 03:46

Type Values Removed Values Added
Summary Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection

28 Jul 2023, 14:13

Type Values Removed Values Added
First Time Feathersjs
Feathersjs feathers-sequelize
CPE cpe:2.3:a:featherjs:feathers-sequelize:*:*:*:*:*:node.js:*:* cpe:2.3:a:feathersjs:feathers-sequelize:*:*:*:*:*:node.js:*:*

28 Feb 2023, 19:06

Type Values Removed Values Added
References (MISC) https://csirt.divd.nl/CVE-2022-29822/ - (MISC) https://csirt.divd.nl/CVE-2022-29822/ - Third Party Advisory
References (MISC) https://csirt.divd.nl/DIVD-2022-00020 - (MISC) https://csirt.divd.nl/DIVD-2022-00020 - Third Party Advisory

06 Jan 2023, 16:15

Type Values Removed Values Added
References
  • {'url': 'https://csirt.divd.nl/cves/CVE-2022-29822/', 'name': 'https://csirt.divd.nl/cves/CVE-2022-29822/', 'tags': ['Broken Link'], 'refsource': 'CONFIRM'}
  • {'url': 'https://csirt.divd.nl/cases/DIVD-2022-00020', 'name': 'https://csirt.divd.nl/cases/DIVD-2022-00020', 'tags': ['Broken Link'], 'refsource': 'CONFIRM'}
  • (MISC) https://csirt.divd.nl/CVE-2022-29822/ -
  • (MISC) https://csirt.divd.nl/DIVD-2022-00020 -

28 Oct 2022, 17:48

Type Values Removed Values Added
References (CONFIRM) https://csirt.divd.nl/cases/DIVD-2022-00020 - (CONFIRM) https://csirt.divd.nl/cases/DIVD-2022-00020 - Broken Link
References (CONFIRM) https://csirt.divd.nl/cves/CVE-2022-29822/ - (CONFIRM) https://csirt.divd.nl/cves/CVE-2022-29822/ - Broken Link
First Time Featherjs
Featherjs feathers-sequelize
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:featherjs:feathers-sequelize:*:*:*:*:*:node.js:*:*
CWE CWE-89

26 Oct 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-26 10:15

Updated : 2024-01-02 19:15


NVD link : CVE-2022-29822

Mitre link : CVE-2022-29822

CVE.ORG link : CVE-2022-29822


JSON object : View

Products Affected

feathersjs

  • feathers-sequelize
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')