REDHAT-BUG-2329287: SQL Injection
Direct usage of the django.db.models.fields.json.HasKey lookup on Oracle is subject to SQL injection if untrusted data is used as a lhs value. Applications that use the lookup through the syntax are unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2329287?
The severity of REDHAT-BUG-2329287 is critical due to the potential for SQL injection vulnerabilities.
How can I fix REDHAT-BUG-2329287?
To fix REDHAT-BUG-2329287, ensure that untrusted data is not used as a lhs value in the django.db.models.fields.json.HasKey lookup.
Who is affected by REDHAT-BUG-2329287?
Applications utilizing Django and employing the django.db.models.fields.json.HasKey lookup on Oracle are affected by REDHAT-BUG-2329287.
What version of Django is impacted by REDHAT-BUG-2329287?
REDHAT-BUG-2329287 impacts versions of Django that use the django.db.models.fields.json.HasKey lookup on Oracle.
When was REDHAT-BUG-2329287 reported?
REDHAT-BUG-2329287 was reported in the context of security vulnerabilities affecting the software.