Back

CRITICAL

python-sqlalchemy: SQL Injection when the order_by parameter can be controlled

Published Feb 20, 2019

Description

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Affected products

Remediation

Red Hat statement

This issue affects the version of python-sqlalchemy(bundled with calamari-server) shipped with Red Hat Ceph Storage 2, as it can be abused by SQL Injection.

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2019
Updated Aug 4, 2024
Reserved Jan 29, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 1, 2019
ENISA EUVD
Assigner mitre
Published Feb 20, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0133 GHSA-887W-45RQ-VXGF