Описание
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 3:5.2.4-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | released | 2:2.2.12-1ubuntu0.29+esm3 |
| esm-infra/xenial | not-affected | code not present |
| jammy | released | 2:3.2.12-2ubuntu1.21 |
| noble | released | 3:4.2.11-1ubuntu1.10 |
| plucky | released | 3:4.2.18-1ubuntu1.4 |
| upstream | released | 3:4.2.24-1 |
Показывать по
EPSS
7.1 High
CVSS3
Связанные уязвимости
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12 ...
Django is subject to SQL injection through its column aliases
EPSS
7.1 High
CVSS3