Описание
In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.15.23 (исключая)Версия от 0.16.0 (включая) до 0.16.6 (исключая)
Одно из
cpe:2.3:a:tortoise_orm_project:tortoise_orm:*:*:*:*:*:*:*:*
cpe:2.3:a:tortoise_orm_project:tortoise_orm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00245
Низкий
6.3 Medium
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
CWE-89
Связанные уязвимости
EPSS
Процентиль: 47%
0.00245
Низкий
6.3 Medium
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
CWE-89