Description
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3024-1 | python-django security update |
Debian DSA |
DSA-4705-1 | python-django security update |
Github GHSA |
GHSA-3gh2-xw74-jmcw | SQL injection in Django |
Ubuntu USN |
USN-4296-1 | Django vulnerability |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:26:16.139Z
Reserved: 2020-02-25T00:00:00.000Z
Link: CVE-2020-9402
No data.
Status : Modified
Published: 2020-03-05T15:15:12.410
Modified: 2024-11-21T05:40:33.953
Link: CVE-2020-9402
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN