Advisories for Pypi/Tortoise-Orm package

2020

SQL injection in Tortoise ORM

Various forms of SQL injection has been found, for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL was only affected when filtering with contains, starts_with or ends_with filters (and their case-insensitive counterparts)