CyberSec.Space Logo
Back to CVE Browser

CVE-2019-14234

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1090%
EPSS Percentile13.02th
PublishedAug 9, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.

Affected Platforms (CPE)

πŸ“¦
Djangoproject

Django

>= 1.11 and < 1.11.23
πŸ“¦
Djangoproject

Django

>= 2.1 and < 2.1.11
πŸ“¦
Djangoproject

Django

>= 2.2 and < 2.2.4
πŸ’»
Fedoraproject

Fedora

= 30
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0

References & Advisories

Related Vulnerabilities