RHSA-2022:5115: Moderate: Red Hat OpenStack Platform 16.2 (python-django20) security update
Security Fix(es): SQL injection in QuerySet.annotate() aggregate() and extra() (CVE-2022-28346)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5115?
The severity of RHSA-2022:5115 is classified as moderate.
How do I fix RHSA-2022:5115?
To fix RHSA-2022:5115, update the affected python-django20 or python3-django20 packages to version 2.0.13-17.el8.
What vulnerability is addressed in RHSA-2022:5115?
RHSA-2022:5115 addresses a SQL injection vulnerability in the QuerySet.annotate(), aggregate(), and extra() methods (CVE-2022-28346).
Which versions are affected by RHSA-2022:5115?
The affected versions for RHSA-2022:5115 are python-django20 and python3-django20 before 2.0.13-17.el8.
Is there a workaround for RHSA-2022:5115?
There is no documented workaround for RHSA-2022:5115; the recommended action is to update to the patched version.