Sensitive Data Exposure in sequelize-cli
Low severity
GitHub Reviewed
Published
Jun 5, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 5, 2019
Published to the GitHub Advisory Database
Jun 5, 2019
Last updated
Jan 9, 2023
Versions of
sequelize-cli
prior to 5.5.0 are vulnerable to Sensitive Data Exposure. The functionfilteredURL()
does not properly sanitize theconfig.password
value which may cause passwords with special characters to be logged in plain text.Recommendation
Upgrade to version 5.5.0 or later.
References