CVE-2024-42005
07.08.2024, 15:15
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.
| Vendor | Product | Version |
|---|---|---|
| djangoproject | django | 4.2 ≤ 𝑥 < 4.2.15 |
| djangoproject | django | 5.0 ≤ 𝑥 < 5.0.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases