Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:9193

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: python3.12-PyMySQL security update

This package contains a pure-Python MySQL client library. The goal of PyMySQL is to be a drop-in replacement for MySQLdb and work on CPython, PyPy, IronPython and Jython.

Security Fix(es):

  • python-pymysql: SQL injection if used with untrusted JSON input (CVE-2024-36039)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
python3.12-PyMySQLnoarch3.el9python3.12-PyMySQL-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQLnoarch3.el9python3.12-PyMySQL-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQLnoarch3.el9python3.12-PyMySQL-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQLnoarch3.el9python3.12-PyMySQL-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQL+rsanoarch3.el9python3.12-PyMySQL+rsa-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQL+rsanoarch3.el9python3.12-PyMySQL+rsa-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQL+rsanoarch3.el9python3.12-PyMySQL+rsa-1.1.0-3.el9.noarch.rpm
python3.12-PyMySQL+rsanoarch3.el9python3.12-PyMySQL+rsa-1.1.0-3.el9.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.

CVSS3: 6.3
redhat
больше 1 года назад

PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.

CVSS3: 6.3
nvd
больше 1 года назад

PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.

CVSS3: 6.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.3
debian
больше 1 года назад

PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON ...