CVE-2019-7548
published 2019-02-06CVE-2019-7548: SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sqlalchemy | < sqlalchemy 1.2.18+ds1-2 (bookworm) | sqlalchemy 1.2.18+ds1-2 (bookworm) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| sqlalchemy | sqlalchemy | — | — |
| sqlalchemy | sqlalchemy | >= 0 < 1.2.18+ds1-2 | 1.2.18+ds1-2 |
| sqlalchemy | sqlalchemy | >= 0 < 1.2.18+ds1-2 | 1.2.18+ds1-2 |
| sqlalchemy | sqlalchemy | >= 0 < 1.2.18+ds1-2 | 1.2.18+ds1-2 |
| sqlalchemy | sqlalchemy | >= 0 < 1.2.18+ds1-2 | 1.2.18+ds1-2 |
| sqlalchemy | sqlalchemy | >= 0 < 1.2.19 | 1.2.19 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH