Skip to content

Unauthenticated arbitrary SQL query execution

Critical
dataflake published GHSA-r3jc-3qmm-w3pw Feb 7, 2024

Package

pip Products.SQLAlchemyDA (pip)

Affected versions

< 2.2

Patched versions

2.2

Description

Impact

The vulnerability allows unauthenticated execution of arbitrary SQL statements on the database the SQLAlchemyDA instance is connected to. All users are affected.

Patches

The problem has been patched in version 2.2.

Workarounds

There is no workaround. All users are urged to upgrade to version 2.2

Severity

Critical

CVE ID

CVE-2024-24811

Weaknesses

No CWEs

Credits