Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-9402

Опубликовано: 04 мар. 2020
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.

A SQL-injection flaw was found in python-django, where GIS functions and aggregates in Oracle did not correctly neutralize tolerance-parameter data. A remote attacker could use this flaw to submit crafted data to inject malicious SQL.

Отчет

Although the following products ship the flawed code, they do not use or support its functionality and therefore will not be updated:

  • Red Hat OpenStack Platform
  • Red Hat Update Infrastructure 3
  • Red Hat Ceph Storage The following products will be updated. However, because both products do not use the functionality, their Impact has been reduced to 'Low':
  • Red Hat Gluster Storage
  • Red Hat Satellite 6

Меры по смягчению последствий

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-djangoWill not fix
Red Hat Ceph Storage 3python-djangoWill not fix
Red Hat OpenStack Platform 10 (Newton)python-djangoWill not fix
Red Hat OpenStack Platform 13 (Queens)python-djangoWill not fix
Red Hat OpenStack Platform 15 (Stein)python-djangoWill not fix
Red Hat OpenStack Platform 16 (Train)python-djangoWill not fix
Red Hat Storage 3python-djangoAffected
Red Hat Update Infrastructure 3 for Cloud Providerspython-djangoFix deferred
Red Hat Satellite 6.9 for RHEL 7pulpFixedRHSA-2021:131321.04.2021
Red Hat Satellite 6.9 for RHEL 7python-djangoFixedRHSA-2021:131321.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=1810088django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle

EPSS

Процентиль: 98%
0.5752
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 5 лет назад

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.

CVSS3: 8.8
nvd
больше 5 лет назад

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.

CVSS3: 8.8
debian
больше 5 лет назад

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 al ...

CVSS3: 8.8
github
около 5 лет назад

SQL injection in Django

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость библиотеки Django для языка программирования Python, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 98%
0.5752
Средний

8.8 High

CVSS3