CVE-2012-0805
Publication date 5 June 2012
Last updated 24 July 2024
Ubuntu priority
Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.
Status
Package | Ubuntu Release | Status |
---|---|---|
keystone | ||
sqlalchemy | ||
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon