PT-2024-20579 · Unknown · Sqlalchemyda

Perrinjerome

·

Published

2024-02-07

·

Updated

2024-02-14

·

CVE-2024-24811

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SQLAlchemyDA versions prior to 2.2
Description A vulnerability in SQLAlchemyDA allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2.
Recommendations For versions prior to 2.2, update to version 2.2 to resolve the issue. As a temporary workaround is not available, upgrading to the patched version is the only recommended course of action.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-24811
GHSA-R3JC-3QMM-W3PW

Affected Products

Sqlalchemyda