Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9: DLA-2811-1 Moderate: SQLAlchemy SQL Injection Threat

Two SQL injection vulnerabilities were discovered in SQLAlchemy, a SQL toolkit and Object Relational Mapper for Python, when the order_by or group_by parameters can be controlled by an attacker. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2811-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany November 06, 2021 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : sqlalchemy Version : 1.0.15+ds1-1+deb9u1 CVE ID : CVE-2019-7164 CVE-2019-7548 Debian Bug : 922669 Two SQL injection vulnerabilities were discovered in SQLAlchemy, a SQL toolkit and Object Relational Mapper for Python, when the order_by or group_by parameters can be controlled by an attacker. Warning: The text coercion feature of SQLAlchemy is rarely used but the warning that has been previously emitted is now an ArgumentError or in case of the order_by() and group_by() parameters a CompileError. For Debian 9 stretch, these problems have been fixed in version 1.0.15+ds1-1+deb9u1. We recommend that you upgrade your sqlalchemy packages. For the detailed security status of sqlalchemy please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sqlalchemy Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2912-1 warns of XSS vulnerabilities in Flask. Immediate update suggested for protection.. SQL Injection, SQLAlchemy Update, Debian Security Advisory. . LinuxSecurity.com Team

Calendar%202 Nov 06, 2021 Debian LTS
197

Debian 8: DLA-1718-1 Critical: SQLAlchemy SQL Injection Issues

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper. . Package : sqlalchemy Version : 0.9.8+dfsg-0.1+deb8u1 CVE ID : CVE-2019-7164 CVE-2019-7548 Debian Bug : 922669 Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper. CVE-2019-7164 SQLAlchemy allows SQL Injection via the order_by parameter. CVE-2019-7548 SQLAlchemy has SQL Injection when the group_by parameter can be controlled. The SQLAlchemy project warns that these security fixes break the seldom-used text coercion feature. For Debian 8 "Jessie", these problems have been fixed in version 0.9.8+dfsg-0.1+deb8u1. We recommend that you upgrade your sqlalchemy packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : sqlalchemy Version : 0.9.8+dfsg-0.1+deb8u1 CVE ID : CVE-2019-7164 CVE-2019-7548 Debian Bug. vulnerabilities, sqlalchemy, python, toolkit, object, relational, mapper. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2019 Critical Debian LTS
87

Debian: DSA-2450-1 Urgent: SQLAlchemy Data Filtering Vulnerability

It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2449-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde April 12, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sqlalchemy Vulnerability : missing input sanitization Problem type : remote Debian-specific: no CVE ID : CVE-2012-0805 It was discovered that sqlalchemy, an SQL toolkit and object relational mapper for python, is not sanitizing input passed to the limit/offset keywords to select() as well as the value passed to select.limit()/offset(). This allows an attacker to perform SQL injection attacks against applications using sqlalchemy that do not implement their own filtering. For the stable distribution (squeeze), this problem has been fixed in version 0.6.3-3+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 0.6.7-1. For the unstable distribution (sid), this problem has been fixed in version 0.6.7-1. We recommend that you upgrade your sqlalchemy packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent SQLAlchemy updates reveal a significant vulnerability linked to input sanitation, increasing the risk of SQL injection attacks on various applications. sqlalchemy, input sanitization, sql injection, debian security, python toolkit. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Apr 12, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200