aiomysql@0.1.0rc1 vulnerabilities

MySQL driver for asyncio.

  • latest version

    0.3.2

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the aiomysql package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    External Control of File Name or Path

    aiomysql is a MySQL driver for asyncio.

    Affected versions of this package are vulnerable to External Control of File Name or Path via the LOAD_LOCAL instruction packet. An attacker can obtain arbitrary files from the client system by setting up a malicious MySQL server that sends crafted instructions to the client, even when client-side restrictions are in place.

    How to fix External Control of File Name or Path?

    Upgrade aiomysql to version 0.3.0 or higher.

    [,0.3.0)