blob: 7a1eac89f131ffbb64e1b2d84d999350f285fe80 [file] [log] [blame]
module: gorm.io/gorm
versions:
- fixed: v0.2.0
description: |
Multiple methods are vulnerable to blind SQL injection attacks
due to constructing SQL statements using unsantized user input.
published: 2021-04-14T12:00:00Z
credit: '@wahyuhadi'
symbols:
- Scope.buildCondition
links:
commit: https://github.com/go-gorm/gorm/commit/836fb2c19d84dac7b0272958dfb9af7cf0d0ade4
context:
- https://github.com/go-gorm/gorm/issues/2517