CVE-2019-14234

Priority
Description
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before
2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key
transformation, key and index lookups for
django.contrib.postgres.fields.JSONField, and key lookups for
django.contrib.postgres.fields.HStoreField, were subject to SQL injection.
This could, for example, be exploited via crafted use of "OR 1=1" in a key
or index name to return all records, using a suitably crafted dictionary,
with dictionary expansion, as the **kwargs passed to the QuerySet.filter()
function.
Assigned-to
mdeslaur
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.8.7-1ubuntu5.10)
Ubuntu 18.04 LTS (Bionic Beaver):released (1:1.11.11-1ubuntu1.5)
Ubuntu 19.04 (Disco Dingo):released (1:1.11.20-1ubuntu0.2)
Ubuntu 19.10 (Eoan):pending (2:2.2.4-1)
More Information

Updated: 2019-08-16 13:14:30 UTC (commit c7022ea67a1624ad82743c35aa6ffe990a7231e1)