First published: Wed Jul 27 2022(Updated: )
Red Hat Update Infrastructure (RHUI) offers a highly scalable, highly redundant framework that enables you to manage repositories and content. It also enables cloud providers to deliver content and updates to Red Hat Enterprise Linux (RHEL) instances.<br>Security Fix:<br><li> Django: Potential SQL injection via Trunc(kind) and Extract(lookup_name) arguments (CVE-2022-34265)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.<br>Users of RHUI are advised to upgrade to this updated package that fixes<br>this bug.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-django | <3.2.14-3.el8 | 3.2.14-3.el8 |
redhat/python38-django | <3.2.14-3.el8 | 3.2.14-3.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:5738 is classified as important.
To fix RHSA-2022:5738, upgrade to the patched version of python-django or python38-django as specified in the advisory.
Versions of python-django up to and including 3.2.14-3.el8 are affected by RHSA-2022:5738.
Yes, RHSA-2022:5738 is relevant for cloud providers that use Red Hat Update Infrastructure to manage RHEL instances.
RHSA-2022:5738 addresses a security vulnerability in Django that affects certain package versions in Red Hat Enterprise Linux.