First published: Thu Nov 28 2024(Updated: )
Direct usage of the django.db.models.fields.json.HasKey lookup on Oracle is subject to SQL injection if untrusted data is used as a lhs value. Applications that use the lookup through the __ syntax are unaffected.
Affected Software | Affected Version | How to fix |
---|---|---|
Django |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2329287 is critical due to the potential for SQL injection vulnerabilities.
To fix REDHAT-BUG-2329287, ensure that untrusted data is not used as a lhs value in the django.db.models.fields.json.HasKey lookup.
Applications utilizing Django and employing the django.db.models.fields.json.HasKey lookup on Oracle are affected by REDHAT-BUG-2329287.
REDHAT-BUG-2329287 impacts versions of Django that use the django.db.models.fields.json.HasKey lookup on Oracle.
REDHAT-BUG-2329287 was reported in the context of security vulnerabilities affecting the software.