Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfg2-wf6j-x53p

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

SQLAlchemy vulnerable to SQL injection

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

Пакеты

Наименование

SQLAlchemy

pip
Затронутые версииВерсия исправления

< 0.7.0b4

0.7.0b4

EPSS

Процентиль: 81%
0.01649
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

ubuntu
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

redhat
больше 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

nvd
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.

debian
около 13 лет назад

Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, a ...

oracle-oval
больше 13 лет назад

ELSA-2012-0369: python-sqlalchemy security update (MODERATE)

EPSS

Процентиль: 81%
0.01649
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89