Description
Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
Remediation
References
https://csirt.divd.nl/CVE-2022-29823/
https://csirt.divd.nl/DIVD-2022-00020
Related Vulnerabilities
CVE-2018-1000174 Vulnerability in maven package org.jenkins-ci.plugins:google-login
CVE-2019-10758 Vulnerability in npm package mongo-express
CVE-2018-20801 Vulnerability in npm package highcharts
CVE-2023-28444 Vulnerability in npm package angular-server-side-configuration
CVE-2018-1999003 Vulnerability in maven package org.jenkins-ci.main:jenkins-core