Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w2r-r2m5-xq5w

Опубликовано: 08 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Django is subject to SQL injection through its column aliases

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 4.2.24

4.2.24

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.0a1, < 5.1.12

5.1.12

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.2a1, < 5.2.6

5.2.6

EPSS

Процентиль: 2%
0.00013
Низкий

7.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

CVSS3: 7.1
redhat
4 месяца назад

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

CVSS3: 7.1
nvd
4 месяца назад

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().

CVSS3: 7.1
debian
4 месяца назад

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12 ...

suse-cvrf
4 месяца назад

Security update for python-Django

EPSS

Процентиль: 2%
0.00013
Низкий

7.1 High

CVSS3

Дефекты

CWE-89