@nozbe/watermelondb/.../watermelondb@0.8.0-1 vulnerabilities

Build powerful React Native and React web apps that scale from hundreds to tens of thousands of records and remain fast

  • latest version

    0.27.1

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @nozbe/watermelondb package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    SQL Injection

    @nozbe/watermelondb is a Reactive & asynchronous database for powerful React and React Native apps.

    Affected versions of this package are vulnerable to SQL Injection. A maliciously crafted record ID can exploit a SQL Injection vulnerability in iOS adapter implementation and cause the app to delete all or selected records from the database, generally causing the app to become unusable.

    How to fix SQL Injection?

    Upgrade @nozbe/watermelondb to version 0.15.1 or higher.

    <0.15.1