CVE-2024-24811Critical· 9.8▾ MidnightSQLAlchemyDA unauthenticated arbitrary SQL query execution
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
The vulnerability allows unauthenticated execution of arbitrary SQL statements on the database the SQLAlchemyDA instance is connected to. All users are affected.
The problem has been patched in version 2.2.
There is no workaround. All users are urged to upgrade to version 2.2
products-sqlalchemyda < 2.2Upgrade to a patched release:
products-sqlalchemyda 2.2