python-sqlalchemy: SQL Injection when the order_by parameter can be controlled
Published Feb 20, 2019
9.3
CRITICALCVSS 4.0
EPSS 3.52%
Description
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Affected products
No data.
Configuration 1
- ≤ 1.2.17
- 1.3.0
- 1.3.0
Configuration 2
- 8.0
- 9.0
Configuration 3
Configuration 4
- 8.0
- 8.1
- 8.2
- 8.4
- 8.2
- 8.4
- 8.2
- 8.4
Configuration 5
- 4.2
- 4.3
No data.
Red Hat Enterprise Linux 8
python27:2.7-8000020190410132513.c0efe978
Fixed · RHSA-2019:0981
Red Hat Enterprise Linux 8
python36:3.6-8000020190410133122.593c47b3
Fixed · RHSA-2019:0984
Red Hat Ceph Storage 2
calamari-server
Will not fix
Red Hat Enterprise Linux 6
python-sqlalchemy
Will not fix
Red Hat Enterprise Linux 7
python-sqlalchemy
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-sqlalchemy
Affected
Red Hat OpenStack Platform 13 (Queens)
python-sqlalchemy
Affected
Red Hat OpenStack Platform 14 (Rocky)
python-sqlalchemy
Affected
Red Hat OpenStack Platform 15 (Stein)
python-sqlalchemy
Affected
Red Hat OpenStack Platform 8 (Liberty)
python-sqlalchemy
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
python-sqlalchemy
Will not fix
Red Hat Software Collections
python27-python-sqlalchemy
Will not fix
Red Hat Software Collections
rh-python35-python-sqlalchemy
Will not fix
Red Hat Software Collections
rh-python36-python-sqlalchemy
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python27:2.7-8000020190410132513.c0efe978 | Fixed | RHSA-2019:0981 |
| Red Hat Enterprise Linux 8 | python36:3.6-8000020190410133122.593c47b3 | Fixed | RHSA-2019:0984 |
| Red Hat Ceph Storage 2 | calamari-server | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | python-sqlalchemy | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | python-sqlalchemy | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-sqlalchemy | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-sqlalchemy | Affected | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-sqlalchemy | Affected | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-sqlalchemy | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | python-sqlalchemy | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-sqlalchemy | Will not fix | n/a |
| Red Hat Software Collections | python27-python-sqlalchemy | Will not fix | n/a |
| Red Hat Software Collections | rh-python35-python-sqlalchemy | Will not fix | n/a |
| Red Hat Software Collections | rh-python36-python-sqlalchemy | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of python-sqlalchemy(bundled with calamari-server) shipped with Red Hat Ceph Storage 2, as it can be abused by SQL Injection.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00087.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00016.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0981 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0984 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-7164 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1678520 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0133 Advisory
- https://github.com/advisories/GHSA-887w-45rq-vxgf Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/sqlalchemy/PYSEC-2019-123.yaml
- https://github.com/sqlalchemy/sqlalchemy/commit/30307c4616ad67c01ddae2e1e8e34fabf6028414
- https://github.com/sqlalchemy/sqlalchemy/issues/4481 x_refsource_MISCExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00020.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00005.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-7164
- https://www.cve.org/CVERecord?id=CVE-2019-7164
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.