Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-28346

Опубликовано: 12 апр. 2022
Источник: ubuntu
Приоритет: high
CVSS2: 7.5
CVSS3: 9.8

Описание

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

РелизСтатусПримечание
bionic

released

1:1.11.11-1ubuntu1.17
devel

released

3.2.12-2ubuntu1
esm-infra-legacy/trusty

not-affected

1.6.11-0ubuntu1.3+esm5
esm-infra/bionic

not-affected

1:1.11.11-1ubuntu1.17
esm-infra/focal

not-affected

2:2.2.12-1ubuntu0.11
esm-infra/xenial

released

1.8.7-1ubuntu5.15+esm5
focal

released

2:2.2.12-1ubuntu0.11
impish

released

2:2.2.24-1ubuntu1.4
jammy

released

3.2.12-2ubuntu1
trusty/esm

released

1.6.11-0ubuntu1.3+esm5

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.4
redhat
около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
nvd
около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.8
debian
около 3 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13 ...

CVSS3: 9.8
github
около 3 лет назад

SQL Injection in Django

CVSS3: 9.8
fstec
около 3 лет назад

Уязвимость реализации методов QuerySet.annotate(), aggregate() и extra() программной платформы для веб-приложений Django, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

7.5 High

CVSS2

9.8 Critical

CVSS3