CVE-2023-39654: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
(updated )
abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.
References
Detect and mitigate CVE-2023-39654 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →