QID 198736

Date Published: 2022-04-13

QID 198736: Ubuntu Security Notification for Django Vulnerabilities (USN-5373-1)

Django incorrectly handled certain certain columnaliases in the queryset.
Django incorrectly handled certain option names inthe queryset.
The django urlvalidator function incorrectly handlednewlines and tabs.

Annotate(), aggregate(), and extra() methods.
Aremote attacker could possibly use this issue to perform an sql injectionattack.
A remote attacker could possibly use thisissue to perform an sql injection attack.
A remote attacker could possibly use this issue toperform a header injection attack.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5373-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198736

    Software Advisories
    Advisory ID Software Component Link
    USN-5373-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5373-1