PulseAugur
实时 23:46:51

Datasette 发布安全修复以解决 SQL 注入漏洞

Datasette 发布了 1.0a38 和 0.65.3 两个版本,以修复一个关键的 SQL 注入漏洞。此安全缺陷可能允许有权访问公共表的用户读取同一数据库内私有表的數據。对于使用 Datasette 权限系统服务混合公共表和私有表的实例,此问题尤为重要。建议管理员在更新之前,禁用受影响数据库的 `execute-sql` 权限。 AI

影响 对 AI 操作的直接影响最小;主要是数据探索工具的软件安全更新。

排序理由 针对特定软件工具的安全修复。

在 Simon Willison 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

Datasette 发布安全修复以解决 SQL 注入漏洞

报道来源 [2]

  1. Simon Willison TIER_1 Italiano(IT) ·

    datasette 1.0a38

    <p><strong>Release:</strong> <a href="https://github.com/simonw/datasette/releases/tag/1.0a38">datasette 1.0a38</a></p> <blockquote> <p>This release fixes a <strong>SQL injection</strong> security issue that affects Datasette instances that serve a <strong>mixture of public and p…

  2. Simon Willison TIER_1 Italiano(IT) ·

    datasette 0.65.3

    <p><strong>Release:</strong> <a href="https://github.com/simonw/datasette/releases/tag/0.65.3">datasette 0.65.3</a></p> <p>Back-ported the SQL Injection security fix from <a href="https://simonwillison.net/2026/Aug/6/datasette/">1.0a38</a>.</p> <p>Tags: <a href="https://simonwill…