FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

py39-sqlalchemy11 -- multiple SQL Injection vulnerabilities

Affected packages
py39-sqlalchemy11 < 1.3.0

Details

VuXML ID 8ccff771-ceca-43a0-85ad-3e595e73b425
Discovery 2019-02-06
Entry 2023-04-09

21k reports:

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

nosecurity reports:

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

References

CVE Name CVE-2019-7164
CVE Name CVE-2019-7548
URL https://osv.dev/vulnerability/GHSA-38fc-9xqv-7f7q
URL https://osv.dev/vulnerability/GHSA-887w-45rq-vxgf
URL https://osv.dev/vulnerability/PYSEC-2019-123
URL https://osv.dev/vulnerability/PYSEC-2019-124