# Security Release for issue #93

**URL:** https://discuss.tryton.org/t/security-release-for-issue-93/7889
**Category:** News
**Tags:** security, python-sql
**Created:** [October 2, 2024, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-93/7889 "2024-10-02T06:00:49Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [October 2, 2024, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-93/7889/1 "2024-10-02T06:00:49Z")

</div>

[Cédric Krier](https://foss.heptapod.net/ced) has found that [python-sql](https://code.tryton.org/python-sql) [does not escape non-Expression for unary operators](https://bugs.tryton.org/python-sql/93) (like `And` and `Or`) which makes any system exposing those vulnerable to an SQL injection attack.

## Impact

[CVSS v3.0 Base Score: 9.1](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L/E:F/RL:O/RC:C/MAV:N/MAC:L/MPR:N/MUI:N/MS:U/MC:N/MI:N/MA:N)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Changed
- Confidentiality: High
- Integrity: Low
- Availability: Low

## Workaround

There is no known workaround.

## Resolution

All affected users should upgrade `python-sql` to the latest version.

Affected versions: \<= 1.5.1  
Non affected versions: \>= 1.5.2

## Reference

- [Unary operators does not escape non-Expression (#93) · Issues · Tryton / python-sql · GitLab](https://bugs.tryton.org/python-sql/93)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/python-sql](https://bugs.tryton.org/python-sql) with the confidential checkbox checked.

---

<div class="post-metadata">

### Author: ![yangoon](https://discuss-cdn.tryton.org/letter_avatar_proxy/v4/letter/y/67e7ee/32.png) [@yangoon](https://discuss.tryton.org/u/yangoon)
#### Post date: [October 10, 2024, 2:19pm UTC](https://discuss.tryton.org/t/security-release-for-issue-93/7889/3 "2024-10-10T14:19:02Z")

</div>

CVE-2024-9774 was assigned to this issue.

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [November 1, 2024, 6:01am UTC](https://discuss.tryton.org/t/security-release-for-issue-93/7889/4 "2024-11-01T06:01:26Z")

</div>

This topic was automatically closed after 29 days. New replies are no longer allowed.
