REDHAT-BUG-2329287: SQL Injection

Published Nov 28, 2024
·
Updated

Direct usage of the django.db.models.fields.json.HasKey lookup on Oracle is subject to SQL injection if untrusted data is used as a lhs value. Applications that use the lookup through the syntax are unaffected.

Affected Software

1 affected component
Django Software Foundation Django

Event History

Nov 28, 2024
Data Sourced
via Red Hat·03:01 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2329287?

The severity of REDHAT-BUG-2329287 is critical due to the potential for SQL injection vulnerabilities.

2

How can I fix REDHAT-BUG-2329287?

To fix REDHAT-BUG-2329287, ensure that untrusted data is not used as a lhs value in the django.db.models.fields.json.HasKey lookup.

3

Who is affected by REDHAT-BUG-2329287?

Applications utilizing Django and employing the django.db.models.fields.json.HasKey lookup on Oracle are affected by REDHAT-BUG-2329287.

4

What version of Django is impacted by REDHAT-BUG-2329287?

REDHAT-BUG-2329287 impacts versions of Django that use the django.db.models.fields.json.HasKey lookup on Oracle.

5

When was REDHAT-BUG-2329287 reported?

REDHAT-BUG-2329287 was reported in the context of security vulnerabilities affecting the software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203