QID 995921
Date Published: 2023-11-16
QID 995921: Python (Pip) Security Update for piccolo (GHSA-xq59-7jf3-rjc6)
The handling of named transaction savepoints in all database implementations is vulnerable to SQL Injection as user provided input is passed directly to connection.execute(...) via f-strings.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xq59-7jf3-rjc6 for updates and patch information.
Vendor References
- GHSA-xq59-7jf3-rjc6 -
github.com/advisories/GHSA-xq59-7jf3-rjc6
CVEs related to QID 995921
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xq59-7jf3-rjc6 | piccolo |
|