Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: alerta-server

Found 1 matching suggestions

View:
Compact
Detailed
Published
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • alerta
    • python312Packages.meteoalertapi
    • python313Packages.meteoalertapi
    • python314Packages.meteoalertapi
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.

Affected products

alerta
  • ==< 9.1.0

Matching in nixpkgs

Ignored packages (4)

pkgs.alerta

Alerta Monitoring System command-line interface

Upstream advisory: https://github.com/alerta/alerta/security/advisories/GHSA-8prr-286p-4w7j