CVE-2024-42005
07.08.2024, 15:15
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.
Vendor | Product | Version |
---|---|---|
djangoproject | django | 4.2 ≤ 𝑥 < 4.2.15 |
djangoproject | django | 5.0 ≤ 𝑥 < 5.0.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases