GHSA-j259-6c58-9m58

    Dashboard / Vulnerabilities / GHSA-j259-6c58-9m58

    GHSA-j259-6c58-9m58

    Published: 11 Aug 2022Last Modified: 8 Nov 2023

    Summary: loopback-connector-postgresql Vulnerable to Improper Sanitization of `contains` Filter

    Details: Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. ### Impact When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality and integrity of data stored on the connected database. This affects users who does any of the following: - Connect to the database via the DataSource with `allowExtendedProperties: true` setting OR - Uses the connector's CRUD methods directly OR - Uses the connector's other methods to interpret the LoopBack filter. ### Patches Patch release `[email protected]` has been published of which resolves this issue. ### Workarounds Users who are unable to upgrade should do the following if applicable: - Remove `allowExtendedProperties: true` DataSource setting - Add `allowExtendedProperties: false` DataSource setting - When passing directly to the connector functions, manually sanitize the user input for the `contains` LoopBack filter beforehand.

    Affected packages

    Package

    Name: loopback-connector-postgresql

    Purl: pkg:npm/loopback-connector-postgresql

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -5.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-j259-6c58-9m58 | CVE-DB