PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3.12-PyMySQL+rsaUpgrade python3.11-PyMySQL+rsaUpgrade python3.11-PyMySQLUpgrade python3.12-PyMySQL | Jul 4, 2024 | May 21, 2024 |
| Debian | — | Upgrade python-pymysql | May 28, 2024 | May 21, 2024 |
| Oracle_linux | — | Upgrade python3.11-PyMySQLUpgrade python3.12-PyMySQLUpgrade python3.11-PyMySQL+rsaUpgrade python3.12-PyMySQL+rsa | Jul 3, 2024 | May 21, 2024 |
| Redhat_linux | — | Upgrade python3.12-PyMySQL+rsaUpgrade python3.11-PyMySQL+rsaUpgrade python3.11-PyMySQLNo solution existsUpgrade python3.12-PyMySQL | Jul 3, 2024 | May 21, 2024 |
| Suse | — | Upgrade python313-PyMySQLUpgrade python311-PyMySQLUpgrade python3-PyMySQL | May 31, 2024 | May 21, 2024 |
| Ubuntu | — | Upgrade python3-pymysql | Jun 6, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub