Описание
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
python-pymysql | fixed | 1.1.1-1 | package |
Примечания
https://github.com/advisories/GHSA-v9hf-5j83-6xpp
https://github.com/PyMySQL/PyMySQL/commit/521e40050cb386a499f68f483fefd144c493053c (v1.1.1)
EPSS
Процентиль: 20%
0.00062
Низкий
Связанные уязвимости
CVSS3: 6.3
ubuntu
около 1 года назад
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
CVSS3: 6.3
redhat
около 1 года назад
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
CVSS3: 6.3
nvd
около 1 года назад
PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
EPSS
Процентиль: 20%
0.00062
Низкий