VDB
Sign up
—

PYSEC-2020-144

Quick fix

PYSEC-2020-144 — tortoise-orm: upgrade to the fixed version with the command below.

pip install --upgrade 'tortoise-orm>=91c364053e0ddf77edc5442914c6f049512678b3'

Details

In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/tortoise-orm
Introduced in: 0Fixed in: 91c364053e0ddf77edc5442914c6f049512678b3
Fixpip install --upgrade 'tortoise-orm>=91c364053e0ddf77edc5442914c6f049512678b3'

References