SQL Injection in pycsw
Critical severity
GitHub Reviewed
Published
Aug 15, 2018
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Package
Affected versions
< 1.8.6
>= 1.10.0, < 1.10.5
>= 2.0.0, < 2.0.2
Patched versions
1.8.6
1.10.5
2.0.2
Description
Published to the GitHub Advisory Database
Aug 15, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 21, 2024
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.
References