SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.
History

Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-07T14:54:41.601Z

Updated: 2025-05-15T19:42:45.806Z

Reserved: 2024-01-31T16:28:17.941Z

Link: CVE-2024-24811

cve-icon Vulnrichment

Updated: 2024-08-01T23:28:12.566Z

cve-icon NVD

Status : Modified

Published: 2024-02-07T15:15:08.507

Modified: 2024-11-21T08:59:45.820

Link: CVE-2024-24811

cve-icon Redhat

No data.