CVE-2024-36039

Publication date 21 May 2024

Last updated 30 May 2025


Ubuntu priority

Cvss 3 Severity Score

6.3 · Medium

Score breakdown

PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.

Status

Package Ubuntu Release Status
python-pymysql 25.04 plucky
Fixed 1.1.1-1ubuntu1
24.10 oracular
Fixed 1.1.1-1ubuntu1
24.04 LTS noble
Fixed 1.0.2-2ubuntu1.1
23.10 mantic
Fixed 1.0.2-1ubuntu1.23.10.1
22.04 LTS jammy
Fixed 1.0.2-1ubuntu1.22.04.1
20.04 LTS focal
Fixed 0.9.3-2ubuntu3.1
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
python-pymysql

Severity score breakdown

Parameter Value
Base score 6.3 · Medium
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L