CVE-2019-7548
06.02.2019, 21:29
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
| Vendor | Product | Version |
|---|---|---|
| sqlalchemy | sqlalchemy | 1.2.17 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | backports_sle | 15.0 |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.1 |
| redhat | enterprise_linux_eus | 8.2 |
| redhat | enterprise_linux_eus | 8.4 |
| redhat | enterprise_linux_server_aus | 8.2 |
| redhat | enterprise_linux_server_aus | 8.4 |
| redhat | enterprise_linux_server_tus | 8.2 |
| redhat | enterprise_linux_server_tus | 8.4 |
| oracle | communications_operations_monitor | 4.2 |
| oracle | communications_operations_monitor | 4.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References