{"id":"CVE-2020-11010","details":"In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and their case-insensitive counterparts).","aliases":["GHSA-9j2c-x8qm-qmjq","PYSEC-2020-144"],"modified":"2026-07-09T00:37:38.585567Z","published":"2020-04-20T22:15:13.587Z","references":[{"type":"ADVISORY","url":"https://github.com/tortoise/tortoise-orm/security/advisories/GHSA-9j2c-x8qm-qmjq"},{"type":"FIX","url":"https://github.com/tortoise/tortoise-orm/commit/91c364053e0ddf77edc5442914c6f049512678b3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tortoise/tortoise-orm","events":[{"introduced":"0"},{"fixed":"d9b0c2ded9ee5a140493f9940dc2abeae4c53aa5"},{"introduced":"558f4651eeb13068b91ff6d50703480cd086fa49"},{"fixed":"50bf70855abbd10833131ff8f8ee3add5a563db7"},{"fixed":"91c364053e0ddf77edc5442914c6f049512678b3"}],"database_specific":{"cpe":"cpe:2.3:a:tortoise_orm_project:tortoise_orm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.15.23"},{"introduced":"0.16.0"},{"fixed":"0.16.6"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.15.22","0.16.5","0.16.4","0.15.21","0.16.3","0.15.20","0.16.2","0.15.19","0.16.1","0.16.0","0.15.18","0.15.17","0.15.16","0.15.15","0.15.14","0.15.13","0.15.12","0.15.11","0.15.10","0.15.9","0.15.8","0.15.7","0.15.6","0.15.5","0.15.4","0.15.3","0.15.2","0.15.1","0.15.0","0.14.0","0.13.7","0.13.6","0.13.5","0.13.4","0.13.3","0.13.2","0.13.1","0.13.0","0.12.7","0.12.6","0.12.5","0.12.4","0.12.3","0.12.2","0.12.1","0.12.0","0.11.13","0.11.12","0.11.11","0.11.10","0.11.9","0.11.8","0.11.7","0.11.6","0.11.5","0.11.4","0.11.3","0.11.2","0.11.1","0.11.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11010.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}