Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-24811


SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.


Published

2024-02-07T15:15:08.507

Last Modified

2024-11-21T08:59:45.820

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zope sqlalchemyda < 2.2 Yes

References