OESA-2022-1642
Dashboard / Vulnerabilities / OESA-2022-1642
OESA-2022-1642
Summary: python-django security update
Details: A high-level Python Web framework that encourages rapid development and clean, pragmatic design. Security Fix(es): An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.(CVE-2022-28346) A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.(CVE-2022-28347)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1642, https://nvd.nist.gov/vuln/detail/CVE-2022-28346, https://nvd.nist.gov/vuln/detail/CVE-2022-28347
Affected packages
Package
Name: python-django
Purl: pkg:rpm/openEuler/python-django&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
