Описание
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
A flaw was found in django. Unsanitized user input passed to QuerySet.order_by()
could bypass intended column reference validation in path marked for deprecation resulting in a potential SQL injection even if a deprecation warning is emitted. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | django | Not affected | ||
Red Hat Ansible Automation Platform 1.2 | python-django | Not affected | ||
Red Hat Ansible Tower 3 | django | Not affected | ||
Red Hat Ceph Storage 2 | calamari-server | Not affected | ||
Red Hat Ceph Storage 2 | python-django | Not affected | ||
Red Hat Ceph Storage 3 | python-django | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-django | Not affected | ||
Red Hat OpenStack Platform 13 (Queens) | python-django | Not affected | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Not affected | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Not affected |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.orde ...
Уязвимость функции QuerySet.order_by() программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольные команды
9.8 Critical
CVSS3