USN-4264-1: Django vulnerability
Published Feb 4, 2020
·Updated
Simon Charette discovered that Django incorrectly handled input in the PostgreSQL module. A remote attacker could possibly use this to perform SQL injection attacks.
Affected Software
1 affected component
pypi/django
Event History
Feb 24, 2026
Advisory Published
via Ubuntu·12:31 AM
Data Sourced
via Ubuntu·12:31 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Django vulnerability?
The vulnerability ID for this Django vulnerability is CVE-2020-7471.
2
What is the severity of CVE-2020-7471?
The severity of CVE-2020-7471 is not specified.
3
How does the Django vulnerability handle input in the PostgreSQL module?
The Django vulnerability incorrectly handles input in the PostgreSQL module.
4
What are the affected versions of Python Django?
The affected versions of Python Django include 1.11.22-1ubuntu1.2 for Ubuntu 19.10 and 1.11.11-1ubuntu1.7 for Ubuntu 18.04.
5
How can I fix the Django vulnerability?
To fix the Django vulnerability, update the Python Django package to versions 1.11.22-1ubuntu1.2 or 1.11.11-1ubuntu1.7 depending on your Ubuntu version.