CVE-2020-11010
Summary
| CVE | CVE-2020-11010 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-20 22:15:00 UTC |
| Updated | 2020-04-28 17:16:00 UTC |
| Description | In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fixed various SQL generation issues · tortoise/tortoise-orm@91c3640 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Various SQL injection attacks have been mitigated. · Advisory · tortoise/tortoise-orm · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983127 Python (pip) Security Update for tortoise-orm (GHSA-9j2c-x8qm-qmjq)