SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-07T14:54:41.601Z

Updated: 2024-08-01T23:28:12.566Z

Reserved: 2024-01-31T16:28:17.941Z

Link: CVE-2024-24811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-02-07T15:15:08.507

Modified: 2024-11-21T08:59:45.820

Link: CVE-2024-24811

cve-icon Redhat

No data.