CVE-2024-24811

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-24811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-24811
Aliases
Published
2024-02-07T14:54:41Z
Modified
2025-11-04T20:16:46.045486Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Products.SQLAlchemyDA vulnerable to unauthenticated arbitrary SQL query execution
Details

SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/zopefoundation/products.sqlalchemyda

Affected ranges

Type
GIT
Repo
https://github.com/zopefoundation/products.sqlalchemyda
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.6.0b
0.6.0b2
0.6.2b2

1.*

1.0.0
1.0.1
1.0.2
1.1.0

2.*

2.0
2.1

v0.*

v0.6.1.a1
v0.6.2b1