Advisories ยป MGASA-2019-0350

Updated python-sqlalchemy packages fix security vulnerabilities

Publication date: 30 Nov 2019
Modification date: 30 Nov 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-7164 , CVE-2019-7548

Description

Updated python-sqlalchemy packages fix security vulnerabilities:

SQL Injection via the order_by parameter (CVE-2019-7164).

SQL Injection via the group_by parameter (CVE-2019-7548).
                

References

SRPMS

7/core