Cédric Krier discovered a vulnerability in python-sql where non-Expression for unary operators are not escaped, making systems vulnerable to SQL injection attacks. The vulnerability has a high confidentiality impact and a low integrity and availability impact, with a CVSS v3.0 Base Score of 9.1. There is no known workaround, and all affected users should upgrade python-sql to the latest version, as versions <= 1.5.1 are affected. Security concerns should be reported on the bug-tracker at https://bugs.tryton.org/python-sql with the confidential checkbox checked.
discuss.tryton.org
discuss.tryton.org
Create attached notes ...