CVE-2016-8640

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-8640
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8640.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-8640
Aliases
Related
Published
2018-08-01T18:29:00Z
Modified
2025-07-01T03:27:16.812878Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.

References

Affected packages

Debian:11 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / pycsw

Package

Name
pycsw
Purl
pkg:deb/debian/pycsw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.2+dfsg-1

Affected versions

1.*

1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.10.4+dfsg-1
1.10.4+dfsg-2

2.*

2.0.0~rc1+dfsg-1~exp1
2.0.0~rc1+dfsg-1~exp2
2.0.0+dfsg-1~exp1
2.0.0+dfsg-1~exp2
2.0.0+dfsg-1~exp3
2.0.0+dfsg-1
2.0.1+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/geopython/pycsw

Affected ranges

Type
GIT
Repo
https://github.com/geopython/pycsw
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.4.0
1.4.0-beta1
1.4.0-rc1
1.4.0-rc2
1.6.0
1.6.0-beta1
1.6.0-rc1
1.8.0
1.8.0-beta1
1.8.0-beta2
1.8.0-rc1
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5