logo

CVE-2020-36645 github.com/square/squalor

Package

Manager: go
Name: github.com/square/squalor
Vulnerable Version: >=0 <0.0.0

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00052 pctl0.15829

Details

Squalor SQL Injection vulnerability A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version v0.0.0 is able to address this issue. The name of the patch is f6f0a47cc344711042eb0970cb423e6950ba3f93. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217623.

Metadata

Created: 2023-01-07T21:30:40Z
Modified: 2023-01-12T23:44:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3hc7-2xcc-7p8f/GHSA-3hc7-2xcc-7p8f.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-3hc7-2xcc-7p8f
Finding: F297
Auto approve: 1