CVE-2019-7164 PUBLISHED

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

EPSS 1.45% · 80.7th percentile

Risk Scores

EPSS Score
1.45%
80.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSsqlalchemy0, 1.1.9+ds1-0ubuntu3, 1.1.9+ds1-0ubuntu4
Ubuntu:16.04:LTSsqlalchemy1.0.8+ds1-1ubuntu5, 1.0.11+ds1-1ubuntu2, 0

Timeline

References

Open in Interactive Console →