VDB
Sign up
MEDIUM6.5

GHSA-6xp3-p59p-q4fj

go-pg SQL injection vulnerability via the component /types/append_value.go

Quick fix

GHSA-6xp3-p59p-q4fj — github.com/go-pg/pg/v10: upgrade to the fixed version with the command below.

go get github.com/go-pg/pg/v10@v10.15.0

Details

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/go-pg/pg/v10
Introduced in: 0Fixed in: 10.15.0
Fixgo get github.com/go-pg/pg/v10@v10.15.0
Go/github.com/go-pg/pg/v9
Introduced in: 0

No fixed version published yet for github.com/go-pg/pg/v9 (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/go-pg/pg
Introduced in: 0

No fixed version published yet for github.com/go-pg/pg (go modules). Pin to a known-safe version or switch to an alternative.

References