DirectorySecurity Advisories
Sign In
Security Advisories

CGA-x7qq-7cr6-xfq4

Published

Last updated

https://images.chainguard.dev/security/CGA-x7qq-7cr6-xfq4
Package

awx

Latest Update
Fixed
Fixed Version

24.6.1-r2

Aliases
  • CVE-2024-53908
  • GHSA-m9g8-fxxm-xg86

Severity

9.8

Critical

CVSS V3

Summary

Django SQL injection in HasKey(lhs, rhs) on Oracle

Description

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images