PyPI: sqlalchemy
CVE-2012-0805
Safety vulnerability ID: SFTY-20120605-17778
Safety legacy ID: pyup.io-52946
Sqlalchemy 0.7.0 includes a fix for CVE-2012-0805: Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function. https://docs.sqlalchemy.org/en/20/changelog/changelog_07.html#change-0.7.0
Overview
SQLAlchemy vulnerable to SQL injection
Advisory
Sqlalchemy 0.7.0 includes a fix for CVE-2012-0805: Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function. https://docs.sqlalchemy.org/en/20/changelog/changelog_07.html#change-0.7.0
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20120605-17778/CVE-2012-0805
- http://rhn.redhat.com/errata/RHSA-2012-0369.html
- http://secunia.com/advisories/48327
- http://secunia.com/advisories/48328
- http://secunia.com/advisories/48771
- http://www.debian.org/security/2012/dsa-2449
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:059
- http://www.sqlalchemy.org/changelog/CHANGES_0_7_0
- http://www.sqlalchemy.org/trac/changeset/852b6a1a87e7/
- https://access.redhat.com/errata/RHSA-2012:0369
- https://access.redhat.com/security/cve/CVE-2012-0805
- https://bugs.launchpad.net/keystone/+bug/918608
- https://bugzilla.redhat.com/show_bug.cgi?id=783305
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0805
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73756
- https://nvd.nist.gov/vuln/detail/CVE-2012-0805
- https://bugs.launchpad.net/keystone/+bug/918608
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73756
- http://rhn.redhat.com/errata/RHSA-2012-0369.html
- http://www.debian.org/security/2012/dsa-2449
- http://www.sqlalchemy.org/changelog/CHANGES_0_7_0
- https://github.com/sqlalchemy/sqlalchemy/commit/51fea2e159ca93daa0bc8066a5c35d8436d99418
- https://web.archive.org/web/20140721183117/http://secunia.com/advisories/48771
- https://web.archive.org/web/20140802043526/http://secunia.com/advisories/48328
- https://web.archive.org/web/20140802044957/http://secunia.com/advisories/48327
- http://www.sqlalchemy.org/trac/changeset/852b6a1a87e7
- https://github.com/pypa/advisory-database/tree/main/vulns/sqlalchemy/PYSEC-2012-9.yaml
- https://github.com/advisories/GHSA-hfg2-wf6j-x53p
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
