mlflow-tracing is vulnerable to SQL Injection
71
High Risk
Affected versions of this package are vulnerable to SQL Injection due to improper neutralization of special elements in SQL commands, specifically where the function.full_name and parameter names (p.name) were directly concatenated into SQL statements without proper escaping or quoting, allowing an attacker with control over these values to inject arbitrary SQL code by crafting malicious function or parameter names containing SQL metacharacters, thereby potentially executing unauthorized commands, accessing, modifying, or deleting sensitive data within the database.
You are affected if you are using a version that falls within the vulnerable range.
mlflow-tracing is vulnerable to SQL Injection in versions 2.14.2 - 3.7.0.
Upgrade the mlflow-tracing library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant