CVE-2026-46374
- EPSS 0.26%
- Veröffentlicht 09.06.2026 22:40:40
- Zuletzt bearbeitet 12.06.2026 14:01:35
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious lon...
CVE-2026-46373
- EPSS 0.26%
- Veröffentlicht 09.06.2026 22:38:33
- Zuletzt bearbeitet 12.06.2026 14:10:04
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious que...
CVE-2023-36830
- EPSS 0.39%
- Veröffentlicht 06.07.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:41
SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential security vulnerability where those users could use the `library_path` config value to allow arbitrary python...