USN-4296-1: Django vulnerability
Published Mar 4, 2020
·Updated
Norbert Szetei discovered that Django incorrectly handled the GIS functions and aggregates on Oracle. A remote attacker could possibly use this issue to perform an SQL injection attack.
Affected Software
1 affected component
pypi/django
Event History
Feb 24, 2026
Advisory Published
via Ubuntu·01:07 AM
Data Sourced
via Ubuntu·01:07 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is USN-4296-1.
2
What is the severity of USN-4296-1?
The severity of USN-4296-1 is not specified.
3
How is Django affected by USN-4296-1?
Django is affected by USN-4296-1 due to incorrect handling of GIS functions and aggregates on Oracle.
4
What is the potential impact of USN-4296-1?
The potential impact of USN-4296-1 is the possibility of a remote attacker performing an SQL injection attack.
5
How can I fix USN-4296-1?
To fix USN-4296-1, update the affected Django package to version 1:1.11.22-1ubuntu1.3 or later.