QID 981481
QID 981481: Python (pip) Security Update for django (GHSA-3gh2-xw74-jmcw)
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3gh2-xw74-jmcw for updates pertaining to this vulnerability.
Vendor References
- GHSA-3gh2-xw74-jmcw -
github.com/advisories/GHSA-3gh2-xw74-jmcw
CVEs related to QID 981481
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3gh2-xw74-jmcw | django |
|