Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-33171

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation
Exploit prediction scoring system (EPSS) score
EPSS Score 0.096
EPSS Ranking 92.5%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-33171
  • Typeorm » Typeorm » Version: 0.0.10
    cpe:2.3:a:typeorm:typeorm:0.0.10
  • Typeorm » Typeorm » Version: 0.0.11
    cpe:2.3:a:typeorm:typeorm:0.0.11
  • Typeorm » Typeorm » Version: 0.0.2
    cpe:2.3:a:typeorm:typeorm:0.0.2
  • Typeorm » Typeorm » Version: 0.0.3
    cpe:2.3:a:typeorm:typeorm:0.0.3
  • Typeorm » Typeorm » Version: 0.0.4
    cpe:2.3:a:typeorm:typeorm:0.0.4
  • Typeorm » Typeorm » Version: 0.0.5
    cpe:2.3:a:typeorm:typeorm:0.0.5
  • Typeorm » Typeorm » Version: 0.0.6
    cpe:2.3:a:typeorm:typeorm:0.0.6
  • Typeorm » Typeorm » Version: 0.0.7
    cpe:2.3:a:typeorm:typeorm:0.0.7
  • Typeorm » Typeorm » Version: 0.0.8
    cpe:2.3:a:typeorm:typeorm:0.0.8
  • Typeorm » Typeorm » Version: 0.0.9
    cpe:2.3:a:typeorm:typeorm:0.0.9
  • Typeorm » Typeorm » Version: 0.1.0
    cpe:2.3:a:typeorm:typeorm:0.1.0
  • Typeorm » Typeorm » Version: 0.1.1
    cpe:2.3:a:typeorm:typeorm:0.1.1
  • Typeorm » Typeorm » Version: 0.1.10
    cpe:2.3:a:typeorm:typeorm:0.1.10
  • Typeorm » Typeorm » Version: 0.1.12
    cpe:2.3:a:typeorm:typeorm:0.1.12
  • Typeorm » Typeorm » Version: 0.1.13
    cpe:2.3:a:typeorm:typeorm:0.1.13
  • Typeorm » Typeorm » Version: 0.1.14
    cpe:2.3:a:typeorm:typeorm:0.1.14
  • Typeorm » Typeorm » Version: 0.1.15
    cpe:2.3:a:typeorm:typeorm:0.1.15
  • Typeorm » Typeorm » Version: 0.1.16
    cpe:2.3:a:typeorm:typeorm:0.1.16
  • Typeorm » Typeorm » Version: 0.1.17
    cpe:2.3:a:typeorm:typeorm:0.1.17
  • Typeorm » Typeorm » Version: 0.1.18
    cpe:2.3:a:typeorm:typeorm:0.1.18
  • Typeorm » Typeorm » Version: 0.1.19
    cpe:2.3:a:typeorm:typeorm:0.1.19
  • Typeorm » Typeorm » Version: 0.1.2
    cpe:2.3:a:typeorm:typeorm:0.1.2
  • Typeorm » Typeorm » Version: 0.1.3
    cpe:2.3:a:typeorm:typeorm:0.1.3
  • Typeorm » Typeorm » Version: 0.1.4
    cpe:2.3:a:typeorm:typeorm:0.1.4
  • Typeorm » Typeorm » Version: 0.1.5
    cpe:2.3:a:typeorm:typeorm:0.1.5
  • Typeorm » Typeorm » Version: 0.1.6
    cpe:2.3:a:typeorm:typeorm:0.1.6
  • Typeorm » Typeorm » Version: 0.1.7
    cpe:2.3:a:typeorm:typeorm:0.1.7
  • Typeorm » Typeorm » Version: 0.1.8
    cpe:2.3:a:typeorm:typeorm:0.1.8
  • Typeorm » Typeorm » Version: 0.1.9
    cpe:2.3:a:typeorm:typeorm:0.1.9
  • Typeorm » Typeorm » Version: 0.2.0
    cpe:2.3:a:typeorm:typeorm:0.2.0
  • Typeorm » Typeorm » Version: 0.2.1
    cpe:2.3:a:typeorm:typeorm:0.2.1
  • Typeorm » Typeorm » Version: 0.2.10
    cpe:2.3:a:typeorm:typeorm:0.2.10
  • Typeorm » Typeorm » Version: 0.2.11
    cpe:2.3:a:typeorm:typeorm:0.2.11
  • Typeorm » Typeorm » Version: 0.2.12
    cpe:2.3:a:typeorm:typeorm:0.2.12
  • Typeorm » Typeorm » Version: 0.2.13
    cpe:2.3:a:typeorm:typeorm:0.2.13
  • Typeorm » Typeorm » Version: 0.2.14
    cpe:2.3:a:typeorm:typeorm:0.2.14
  • Typeorm » Typeorm » Version: 0.2.15
    cpe:2.3:a:typeorm:typeorm:0.2.15
  • Typeorm » Typeorm » Version: 0.2.16
    cpe:2.3:a:typeorm:typeorm:0.2.16
  • Typeorm » Typeorm » Version: 0.2.17
    cpe:2.3:a:typeorm:typeorm:0.2.17
  • Typeorm » Typeorm » Version: 0.2.18
    cpe:2.3:a:typeorm:typeorm:0.2.18
  • Typeorm » Typeorm » Version: 0.2.19
    cpe:2.3:a:typeorm:typeorm:0.2.19
  • Typeorm » Typeorm » Version: 0.2.2
    cpe:2.3:a:typeorm:typeorm:0.2.2
  • Typeorm » Typeorm » Version: 0.2.20
    cpe:2.3:a:typeorm:typeorm:0.2.20
  • Typeorm » Typeorm » Version: 0.2.21
    cpe:2.3:a:typeorm:typeorm:0.2.21
  • Typeorm » Typeorm » Version: 0.2.22
    cpe:2.3:a:typeorm:typeorm:0.2.22
  • Typeorm » Typeorm » Version: 0.2.23
    cpe:2.3:a:typeorm:typeorm:0.2.23
  • Typeorm » Typeorm » Version: 0.2.24
    cpe:2.3:a:typeorm:typeorm:0.2.24
  • Typeorm » Typeorm » Version: 0.2.25
    cpe:2.3:a:typeorm:typeorm:0.2.25
  • Typeorm » Typeorm » Version: 0.2.26
    cpe:2.3:a:typeorm:typeorm:0.2.26
  • Typeorm » Typeorm » Version: 0.2.3
    cpe:2.3:a:typeorm:typeorm:0.2.3
  • Typeorm » Typeorm » Version: 0.2.4
    cpe:2.3:a:typeorm:typeorm:0.2.4
  • Typeorm » Typeorm » Version: 0.2.5
    cpe:2.3:a:typeorm:typeorm:0.2.5
  • Typeorm » Typeorm » Version: 0.2.6
    cpe:2.3:a:typeorm:typeorm:0.2.6
  • Typeorm » Typeorm » Version: 0.2.7
    cpe:2.3:a:typeorm:typeorm:0.2.7
  • Typeorm » Typeorm » Version: 0.2.8
    cpe:2.3:a:typeorm:typeorm:0.2.8
  • Typeorm » Typeorm » Version: 0.2.9
    cpe:2.3:a:typeorm:typeorm:0.2.9


Contact Us

Shodan ® - All rights reserved