suse · CVE-2019-7548

Quick triage

Priority: high Published: 2021-05-30 14:24:26 UTC Updated: 2026-03-05 06:25:13 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-7548 severity important: SUSE including 258 source package names (ardana-ansible-9.0+git.1566374020.301191f-3.7.2, ardana-barbican-9.0+git.1566251498.be02ca4-3.7.2, …), 372 product×package rows across 24 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 4, … (24 product lines)): Fixed 372.

Description:

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

cvelogic Threat Intelligence