CVE-2020-36645 – github.com/square/squalor
Package
Manager: go
Name: github.com/square/squalor
Vulnerable Version: >=0 <0.0.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00052 pctl0.15829
Details
Squalor SQL Injection vulnerability A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection. Upgrading to version v0.0.0 is able to address this issue. The name of the patch is f6f0a47cc344711042eb0970cb423e6950ba3f93. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217623.
Metadata
Created: 2023-01-07T21:30:40Z
Modified: 2023-01-12T23:44:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3hc7-2xcc-7p8f/GHSA-3hc7-2xcc-7p8f.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-3hc7-2xcc-7p8f
Finding: F297
Auto approve: 1