{"id":"CVE-2022-2422","details":"Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.","aliases":["GHSA-qpv8-4pjq-qqh7"],"modified":"2026-03-14T00:45:39.147254Z","published":"2022-10-26T10:15:16.993Z","references":[{"type":"ADVISORY","url":"https://csirt.divd.nl/CVE-2022-2422"},{"type":"ADVISORY","url":"https://csirt.divd.nl/DIVD-2022-00020"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/feathersjs-ecosystem/feathers-sequelize","events":[{"introduced":"51d4360d66851596a71d7d274c4135d025ee170b"},{"fixed":"0f2edef8593f5e81195d47f89931f147a96664e7"}],"database_specific":{"versions":[{"introduced":"6.0.0"},{"fixed":"6.3.4"}]}}],"versions":["v6.0.0","v6.0.1","v6.0.2","v6.1.0","v6.2.0","v6.3.0","v6.3.1","v6.3.2","v6.3.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2422.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}