CVE-2016-8640

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-8640
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8640.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-8640
Aliases
Downstream
Published
2018-08-01T18:29:00.220Z
Modified
2025-11-14T04:50:26.023071Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References

Affected packages

Git / github.com/geopython/pycsw

Affected ranges

Type
GIT
Repo
https://github.com/geopython/pycsw
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.4.0
1.4.0-beta1
1.4.0-rc1
1.4.0-rc2
1.6.0
1.6.0-beta1
1.6.0-rc1
1.8.0
1.8.0-beta1
1.8.0-beta2
1.8.0-rc1
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8640.json"