SQLAlchemyDA unauthenticated arbitrary SQL query execution
Critical severity
GitHub Reviewed
Published
Feb 7, 2024
in
zopefoundation/Products.SQLAlchemyDA
•
Updated Feb 14, 2024
Description
Published by the National Vulnerability Database
Feb 7, 2024
Published to the GitHub Advisory Database
Feb 7, 2024
Reviewed
Feb 7, 2024
Last updated
Feb 14, 2024
Impact
The vulnerability allows unauthenticated execution of arbitrary SQL statements on the database the SQLAlchemyDA instance is connected to. All users are affected.
Patches
The problem has been patched in version 2.2.
Workarounds
There is no workaround. All users are urged to upgrade to version 2.2
References