CVE-2022-28347
12.04.2022, 05:15
A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.
Vendor | Product | Version |
---|---|---|
djangoproject | django | 2.2 ≤ 𝑥 < 2.2.28 |
djangoproject | django | 3.2 ≤ 𝑥 < 3.2.13 |
djangoproject | django | 4.0 ≤ 𝑥 < 4.0.4 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References