CVE-2016-8640

Source
https://cve.org/CVERecord?id=CVE-2016-8640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-8640
Aliases
Downstream
Published
2018-08-01T18:29:00.220Z
Modified
2026-04-01T23:55:08.122223Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References

Affected packages

Git / github.com/geopython/pycsw

Affected ranges

Type
GIT
Repo
https://github.com/geopython/pycsw
Events
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.8.6"
        },
        {
            "introduced": "1.10.0"
        },
        {
            "fixed": "1.10.5"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.0.2"
        }
    ]
}

Affected versions

0.*
0.1.0
1.*
1.0.0
1.0.0-beta1
1.0.0-beta2
1.0.0-rc1
1.10.0
1.10.0-beta1
1.10.0-rc1
1.10.1
1.10.2
1.10.3
1.10.4
1.2.0
1.2.0-beta1
1.2.0-rc1
1.4.0
1.4.0-beta1
1.4.0-rc1
1.4.0-rc2
1.4.1
1.4.2
1.6.0
1.6.0-beta1
1.6.0-rc1
1.6.1
1.6.2
1.6.3
1.6.4
1.8.0
1.8.0-beta1
1.8.0-beta2
1.8.0-rc1
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
2.*
2.0.0
2.0.0-alpha1
2.0.0-rc1
2.0.1
2.2.0
2.4.0
2.4.1
2.4.2
2.6.0
2.6.1
2.6.2
2.8.0-alpha1
2.8.0-alpha2
3.*
3.0.0-alpha1
3.0.0-alpha2
3.0.0-alpha3
3.0.0-alpha4
3.0.0-alpha5
3.0.0-alpha6
3.0.0-alpha7
3.0.0-beta1
3.0.0-beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8640.json"