QID 983492
QID 983492: Python (pip) Security Update for pycsw (GHSA-hg4c-rgvm-964g)
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hg4c-rgvm-964g for updates pertaining to this vulnerability.
Vendor References
- GHSA-hg4c-rgvm-964g -
github.com/advisories/GHSA-hg4c-rgvm-964g
CVEs related to QID 983492
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hg4c-rgvm-964g | pycsw |
|