Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-28346

Опубликовано: 12 апр. 2022
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed2:3.2.13-1package

Примечания

  • https://www.djangoproject.com/weblog/2022/apr/11/security-releases/

  • https://github.com/django/django/commit/93cae5cb2f9a4ef1514cf1a41f714fef08005200 (main)

  • https://github.com/django/django/commit/800828887a0509ad1162d6d407e94d8de7eafc60 (4.0.4)

  • https://github.com/django/django/commit/2044dac5c6968441be6f534c4139bcf48c5c7e48 (3.2.13)

  • https://github.com/django/django/commit/2c09e68ec911919360d5f8502cefc312f9e03c5d (2.2.28)

EPSS

Процентиль: 83%
0.02039
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.4
redhat
больше 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
nvd
больше 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
github
больше 3 лет назад

SQL Injection in Django

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость реализации методов QuerySet.annotate(), aggregate() и extra() программной платформы для веб-приложений Django, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 83%
0.02039
Низкий