SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-07T14:54:41.601Z

Updated: 2024-02-07T14:54:41.601Z

Reserved: 2024-01-31T16:28:17.941Z


Link: CVE-2024-24811

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-02-07T15:15:08.507

Modified: 2024-02-14T20:26:39.143


Link: CVE-2024-24811

JSON object: View

cve-icon Redhat Information

No data.

CWE