CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-14234

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1090%
EPSS Percentile13.02th
Published2019年8月9日
Last Modified2024年11月21日

Vulnerability Description

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.

Affected Platforms (CPE)

📦
Djangoproject

Django

>= 1.11 and < 1.11.23
📦
Djangoproject

Django

>= 2.1 and < 2.1.11
📦
Djangoproject

Django

>= 2.2 and < 2.2.4
💻
Fedoraproject

Fedora

= 30
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0

References & Advisories

相關漏洞威脅

CVE-2019-14234 Detail & Impact Analysis | CVSS 9.8 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space