CVE-2022-34265
python-django: Potential SQL injection via Trunc(kind) and Extract(lookup_name) arguments
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
Se ha detectado un problema en Django versiones 3.2 anteriores a 3.2.14 y 4.0 anteriores a 4.0.6. Las funciones de base de datos Trunc() y Extract() están sujetas a inyección SQL si son usados datos no confiables como valor de kind/lookup_name. Las aplicaciones que restringen el nombre de búsqueda y la elección del tipo a una lista segura conocida no están afectadas
A flaw was found in Django. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-21 CVE Reserved
- 2022-07-04 CVE Published
- 2022-07-13 First Exploit
- 2024-08-03 CVE Updated
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://groups.google.com/forum/#%21forum/django-announce | ||
https://security.netapp.com/advisory/ntap-20220818-0006 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/aeyesec/CVE-2022-34265 | 2022-07-30 | |
https://github.com/ZhaoQi99/CVE-2022-34265 | 2022-08-25 | |
https://github.com/traumatising/CVE-2022-34265 | 2022-07-13 |
URL | Date | SRC |
---|---|---|
https://docs.djangoproject.com/en/4.0/releases/security | 2023-11-07 | |
https://www.djangoproject.com/weblog/2022/jul/04/security-releases | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | >= 3.2 < 3.2.14 Search vendor "Djangoproject" for product "Django" and version " >= 3.2 < 3.2.14" | - |
Affected
| ||||||
Djangoproject Search vendor "Djangoproject" | Django Search vendor "Djangoproject" for product "Django" | >= 4.0 < 4.0.6 Search vendor "Djangoproject" for product "Django" and version " >= 4.0 < 4.0.6" | - |
Affected
|