QID 980202
QID 980202: Python (pip) Security Update for SQLAlchemy (GHSA-887w-45rq-vxgf)
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-887w-45rq-vxgf for updates pertaining to this vulnerability.
Vendor References
- GHSA-887w-45rq-vxgf -
github.com/advisories/GHSA-887w-45rq-vxgf
CVEs related to QID 980202
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-887w-45rq-vxgf | SQLAlchemy |
|