Activity log for bug #1862382

Date Who What changed Old value New value Message
2020-02-07 15:48:23 Bin Qian bug added bug
2020-02-07 15:55:21 Bin Qian description security vulnerability found in requirement.txt 2 SQLAlchemy vulnerabilities found in …/sources/requirements.txt Remediation Upgrade SQLAlchemy to version 1.3.0 or later. For example: SQLAlchemy>=1.3.0 Always verify the validity and compatibility of suggestions with your codebase. security vulnerability found in requirement.txt 2 SQLAlchemy vulnerabilities found in …/sources/requirements.txt Remediation Upgrade SQLAlchemy to version 1.3.0 or later. For example: SQLAlchemy>=1.3.0 Always verify the validity and compatibility of suggestions with your codebase. CVE-2019-7164 moderate severity Vulnerable versions: < 1.3.0 Patched version: 1.3.0 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. CVE-2019-7548 moderate severity Vulnerable versions: < 1.3.0 Patched version: 1.3.0 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
2020-02-10 15:01:07 Ghada Khalil starlingx: importance Undecided Low
2020-02-10 15:01:09 Ghada Khalil starlingx: status New Triaged
2020-02-10 15:01:19 Ghada Khalil starlingx: assignee Al Bailey (albailey1974)
2020-02-10 15:01:26 Ghada Khalil tags stx.security