Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg4c-rgvm-964g

Опубликовано: 15 авг. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

SQL Injection in pycsw

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

Пакеты

Наименование

pycsw

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.2

2.0.2

Наименование

pycsw

pip
Затронутые версииВерсия исправления

< 1.8.6

1.8.6

Наименование

pycsw

pip
Затронутые версииВерсия исправления

>= 1.10.0, < 1.10.5

1.10.5

EPSS

Процентиль: 75%
0.00905
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 7 лет назад

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

CVSS3: 9.1
nvd
больше 7 лет назад

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

CVSS3: 9.1
debian
больше 7 лет назад

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10 ...

EPSS

Процентиль: 75%
0.00905
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-89