{"id":"GHSA-fx4w-v43j-vc45","summary":"SQL injection in typeORM","details":"The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation.","aliases":["CVE-2022-33171"],"modified":"2024-03-21T19:12:58.107504Z","published":"2022-07-05T00:00:54Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-03-21T18:57:32Z","nvd_published_at":"2022-07-04T16:15:00Z","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33171"},{"type":"WEB","url":"https://github.com/typeorm/typeorm/compare/0.2.45...0.3.0"},{"type":"WEB","url":"https://seclists.org/fulldisclosure/2022/Jun/51"},{"type":"WEB","url":"http://packetstormsecurity.com/files/168096/TypeORM-0.3.7-Information-Disclosure.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2022/Aug/7"}],"affected":[{"package":{"name":"typeorm","ecosystem":"npm","purl":"pkg:npm/typeorm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-fx4w-v43j-vc45/GHSA-fx4w-v43j-vc45.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}