CVE-2024-9774
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
A vulnerability was found in python-sql where unary operators do not escape non-Expression.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0024
Percentile
0,5th
Updated
EPSS Score Trend (Last 90 Days)
150
Improper Neutralization of Escape, Meta, or Control Sequences
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Unexpected State
Applicable Platforms
All platforms may be affected
https://lists.debian.org/debian-lts-announce/2024/10/msg00023.html
https://access.redhat.com/security/cve/CVE-2024-9774
https://bugzilla.redhat.com/show_bug.cgi?id=2332734
https://discuss.tryton.org/t/security-release-for-issue-93/7889/3