QID 981594
QID 981594: Python (pip) Security Update for django (GHSA-hmr4-m2h5-33qx)
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hmr4-m2h5-33qx for updates pertaining to this vulnerability.
Vendor References
- GHSA-hmr4-m2h5-33qx -
github.com/advisories/GHSA-hmr4-m2h5-33qx
CVEs related to QID 981594
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hmr4-m2h5-33qx | django |
|