PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 8 | RedHat | python3.11-PyMySQL-0:1.0.2-2.el8_10 | * |
Red Hat Enterprise Linux 8 | RedHat | python3.12-PyMySQL-0:1.1.0-3.el8_10 | * |
Red Hat Enterprise Linux 9 | RedHat | python3.12-PyMySQL-0:1.1.0-3.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | python3.11-PyMySQL-0:1.0.2-2.el9 | * |
Python-pymysql | Ubuntu | devel | * |
Python-pymysql | Ubuntu | focal | * |
Python-pymysql | Ubuntu | jammy | * |
Python-pymysql | Ubuntu | mantic | * |
Python-pymysql | Ubuntu | noble | * |
Python-pymysql | Ubuntu | oracular | * |
Python-pymysql | Ubuntu | upstream | * |