First published: Wed Apr 06 2022(Updated: )
``QuerySet.annotate()`, ``aggregate()``, and ``extra()`` methods were subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the ``**kwargs`` passed to these methods. This issue has High severity, according to the Django security policy [1].
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/automation-controller | <0:4.1.2-2.el8a | 0:4.1.2-2.el8a |
redhat/python-django | <0:3.2.13-1.el8 | 0:3.2.13-1.el8 |
redhat/python3-django | <0:2.2.28-1.el7 | 0:2.2.28-1.el7 |
redhat/python3-django | <0:2.2.28-1.el8 | 0:2.2.28-1.el8 |
redhat/python-django20 | <0:2.0.13-18.el8 | 0:2.0.13-18.el8 |
redhat/python-django20 | <0:2.0.13-17.el8 | 0:2.0.13-17.el8 |
redhat/python-django | <0:3.2.13-2.el8 | 0:3.2.13-2.el8 |
redhat/python-pulpcore | <0:3.17.6-3.el8 | 0:3.17.6-3.el8 |
Djangoproject Django | >=2.2<2.2.28 | |
Djangoproject Django | >=3.2<3.2.13 | |
Djangoproject Django | >=4.0<4.0.4 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =11.0 | |
pip/Django | >=4.0<4.0.4 | 4.0.4 |
pip/Django | >=3.2<3.2.13 | 3.2.13 |
pip/Django | >=2.2<2.2.28 | 2.2.28 |
debian/2:3.2.12-2 | ||
debian/1:1.10.7-2+deb9u15 | ||
debian/2:2.2.26-1~deb11u1 | ||
debian/python-django | <=1:1.11.29-1~deb10u1 | 1:1.11.29-1+deb10u10 2:2.2.28-1~deb11u2 3:3.2.19-1+deb12u1 3:3.2.21-1 3:4.2.8-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-28346 refers to a SQL injection vulnerability in the Django package.
CVE-2022-28346 is considered critical with a severity score of 9.8.
Django versions 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4 are affected by CVE-2022-28346.
To fix CVE-2022-28346, update Django to versions 2.2.28, 3.2.13, or 4.0.4 or later.
You can find more information about CVE-2022-28346 in the official CVE record, NVD database, Django website, Bugzilla, and Red Hat Security Advisories.