CVE-2019-7548: SQL Injection
Published Feb 1, 2019
·Updated
A vulnerability was found in SQLAlchemy 1.2.17. An SQL Injection when the groupby parameter can be controlled.
References: https://github.com/no-security/sqlalchemytest
Other sources
SQLAlchemy 1.2.17 has SQL Injection when the groupby parameter can be controlled.
Affected Software
17 affected componentsFixes available
pip/SQLAlchemy<1.2.19
1.2.19
SQLAlchemy SQLAlchemy=1.2.17
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Backports SLE=15.0
openSUSE Leap=15.0
openSUSE Leap=15.1
redhat Enterprise Linux=8.0
redhat Enterprise Linux Eus=8.1
redhat Enterprise Linux Eus=8.2
redhat Enterprise Linux Eus=8.4
redhat Enterprise Linux Server Aus=8.2
redhat Enterprise Linux Server Aus=8.4
redhat Enterprise Linux Server Tus=8.2
redhat Enterprise Linux Server Tus=8.4
Oracle Communications Operations Monitor=4.2
Oracle Communications Operations Monitor=4.3
Remediation
Patch Available
Event History
Feb 1, 2019
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 6, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 8, 2019
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Apr 16, 2019
Advisory Published
via GitHub·03:50 PM
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is CVE-2019-7548?
CVE-2019-7548 is a vulnerability in SQLAlchemy 1.2.17 that allows SQL injection when the group_by parameter can be controlled.
2
What is the severity of CVE-2019-7548?
CVE-2019-7548 has a severity rating of 7.8, which is considered high.
3
Which software versions are affected by CVE-2019-7548?
SQLAlchemy versions up to 1.2.17 are affected by CVE-2019-7548.
4
How do I fix CVE-2019-7548?
To fix CVE-2019-7548, update to SQLAlchemy version 1.3.0 or higher.
5
Where can I find more information about CVE-2019-7548?
You can find more information about CVE-2019-7548 at the following references: [link1], [link2], [link3].