USN-6801-1: PyMySQL vulnerability
30 May 2024
PyMySQL could be vulnerable to SQL injection attacks.
Releases
Packages
- python-pymysql - Pure-Python MySQL driver
Details
It was discovered that PyMySQL incorrectly escaped untrusted JSON input. An
attacker could possibly use this issue to perform SQL injection attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.