CVE-2019-7548 PUBLISHED

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

EPSS 1.18% · 78.6th percentile

Risk Scores

EPSS Score
1.18%
78.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsqlalchemy0, 1.0.8+ds1-1ubuntu5, 1.0.11+ds1-1ubuntu2
Ubuntu:18.04:LTSsqlalchemy0, 1.1.9+ds1-0ubuntu3, 1.1.9+ds1-0ubuntu4

Timeline

References

Open in Interactive Console →