PT-2018-5042 · Pycsw · Pycsw

Publicado

2018-08-01

·

Atualizado

2019-10-09

·

CVE-2016-8640

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pycsw versions prior to 2.0.2 pycsw versions prior to 1.10.5 pycsw versions prior to 1.8.6
Description A SQL injection issue affects the pycsw database, allowing unauthorized access to read and extract data from any table that the database user has access to. On PostgreSQL, it is also possible to perform updates, inserts, deletes, and modify the database in any table the database user has access to.
Recommendations For versions prior to 2.0.2, update to version 2.0.2 or later. For versions prior to 1.10.5, update to version 1.10.5 or later. For versions prior to 1.8.6, update to version 1.8.6 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8640
GHSA-HG4C-RGVM-964G
PYSEC-2018-98

Produtos afetados

Pycsw