{"id":"GHSA-gmpq-xrxj-xh8m","summary":"Arches vulnerable to execution of arbitrary SQL","details":"### Impact\nWith a carefully crafted web request, it's possible to execute certain unwanted sql statements against the database.  \nAnyone running the impacted versions (\u003c=6.1.1, 6.2.0, \u003e=7.0.0, \u003c=7.1.1) should upgrade as soon as possible.\n\n### Patches\nThe problem has been patched in the following versions: [6.1.2](https://pypi.org/project/arches/6.1.2/), [6.2.1](https://pypi.org/project/arches/6.2.1/), and [7.2.0](https://pypi.org/project/arches/7.2.0/)\nUsers are strongly urged to upgrade to the most recent relevant patch.\n\n### Workarounds\nThere are no workarounds.\n\n### General References \nhttps://www.w3schools.com/sql/sql_injection.asp\nhttps://en.wikipedia.org/wiki/SQL_injection\n\n### For more information\nPost any questions to the [Arches project forum](https://community.archesproject.org/).\n","aliases":["CVE-2022-41892","PYSEC-2022-42985"],"modified":"2025-02-17T05:28:06.949459Z","published":"2022-11-11T00:05:15Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-11-11T00:05:15Z","nvd_published_at":"2022-11-11T04:15:00Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/archesproject/arches/security/advisories/GHSA-gmpq-xrxj-xh8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41892"},{"type":"WEB","url":"https://github.com/archesproject/arches/commit/7ed53e23a616edf3301d95814d9d64de5e3072a9"},{"type":"PACKAGE","url":"https://github.com/archesproject/arches"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/arches/PYSEC-2022-42985.yaml"},{"type":"WEB","url":"https://pypi.org/project/arches/6.1.2"},{"type":"WEB","url":"https://pypi.org/project/arches/7.2.0"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2022-070_GHSL-2022-072_Arches"}],"affected":[{"package":{"name":"arches","ecosystem":"PyPI","purl":"pkg:pypi/arches"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.2"}]}],"versions":["3.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0rc10","3.0rc11","3.0rc12","3.0rc13","3.0rc14","3.0rc6","3.0rc7","3.0rc8","3.0rc9","3.1","3.1.1","3.1.2","4.0","4.0.1","4.0b0","4.0b1","4.0b2","4.0b3","4.1","4.1.1","4.2","4.3","4.3.1","4.3.2","4.3.3","4.4","4.4.1","4.4.2","4.4.3","5.0","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","6.0.0","6.0.1","6.1.0","6.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-gmpq-xrxj-xh8m/GHSA-gmpq-xrxj-xh8m.json"}},{"package":{"name":"arches","ecosystem":"PyPI","purl":"pkg:pypi/arches"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.1"}]}],"versions":["6.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-gmpq-xrxj-xh8m/GHSA-gmpq-xrxj-xh8m.json"}},{"package":{"name":"arches","ecosystem":"PyPI","purl":"pkg:pypi/arches"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.2.0"}]}],"versions":["7.0.0","7.1.0","7.1.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.1.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-gmpq-xrxj-xh8m/GHSA-gmpq-xrxj-xh8m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"}]}