CVE-2023-22580

Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
DIVDCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
VendorProductVersion
sequelizejssequelize
𝑥
< 6.28.1
sequelizejssequelize
7.0.0:alpha1
sequelizejssequelize
7.0.0:alpha10
sequelizejssequelize
7.0.0:alpha11
sequelizejssequelize
7.0.0:alpha12
sequelizejssequelize
7.0.0:alpha13
sequelizejssequelize
7.0.0:alpha14
sequelizejssequelize
7.0.0:alpha15
sequelizejssequelize
7.0.0:alpha16
sequelizejssequelize
7.0.0:alpha17
sequelizejssequelize
7.0.0:alpha18
sequelizejssequelize
7.0.0:alpha19
sequelizejssequelize
7.0.0:alpha2
sequelizejssequelize
7.0.0:alpha2.1
sequelizejssequelize
7.0.0:alpha2.2
sequelizejssequelize
7.0.0:alpha3
sequelizejssequelize
7.0.0:alpha4
sequelizejssequelize
7.0.0:alpha5
sequelizejssequelize
7.0.0:alpha6
sequelizejssequelize
7.0.0:alpha7
sequelizejssequelize
7.0.0:alpha8
sequelizejssequelize
7.0.0:alpha9
sequelizejssequelize
7.0.0:oc_test_1
sequelizejssequelize
7.0.0:oc_test_2
sequelizejssequelize
7.0.0:oc_test_3
sequelizejssequelize
7.0.0:oc_test_4
𝑥
= Vulnerable software versions