Description
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2982-1 | python-django security update |
Debian DSA |
DSA-5254-1 | python-django security update |
EUVD |
EUVD-2022-0087 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs. |
Github GHSA |
GHSA-2gwj-7jmv-h26r | SQL Injection in Django |
Ubuntu USN |
USN-5373-1 | Django vulnerabilities |
Ubuntu USN |
USN-5373-2 | Django vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-13T16:32:33.638Z
Reserved: 2022-04-02T00:00:00.000Z
Link: CVE-2022-28346
No data.
Status : Modified
Published: 2022-04-12T05:15:06.927
Modified: 2024-11-21T06:57:11.007
Link: CVE-2022-28346
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN