Skip to content

Backporting attributes vulnerability fix to v.6.x (CVE-2023-22578) #15694

Answered by ephys
panusoi asked this question in Help & Questions
Discussion options

You must be logged in to vote

Hi!

At the present time I do not know.

The problem is that, while I did make the changes to remove a footgun in v7, that behavior was not a bug but a deliberate feature implemented by one of the previous teams that worked on Sequelize, and there are codebases relying on it.

Backporting #15374 would introduce a breaking change in a minor release. We've exceptionally done that in the past when we fixed a major issue (#14519), but I am not convinced that it's warranted for this one.

The reason I think releasing this breaking change in a minor release is unwarranted is that it can only be a problem if you use user-provided values as the name of a column to select. Even without the fix, you sh…

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@usmansagri

This comment was marked as off-topic.

@ephys

This comment was marked as off-topic.

Answer selected by panusoi
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants