UBUNTU-CVE-2024-53908

Source
https://ubuntu.com/security/CVE-2024-53908
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-53908.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-53908
Related
Published
2024-12-04T15:00:00Z
Modified
2025-01-13T10:26:50Z
Summary
[none]
Details

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.haskey lookup via _ are unaffected.)

References

Affected packages

Ubuntu:24.10 / python-django

Package

Name
python-django
Purl
pkg:deb/ubuntu/python-django@3:4.2.15-1ubuntu1.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3:4.2.15-1ubuntu1.1

Affected versions

3:4.*

3:4.2.11-1ubuntu1
3:4.2.13-1
3:4.2.14-1
3:4.2.15-1
3:4.2.15-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "3:4.2.15-1ubuntu1.1",
            "binary_name": "python-django-doc"
        },
        {
            "binary_version": "3:4.2.15-1ubuntu1.1",
            "binary_name": "python3-django"
        }
    ]
}

Ubuntu:24.04:LTS / python-django

Package

Name
python-django
Purl
pkg:deb/ubuntu/python-django@3:4.2.11-1ubuntu1.4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3:4.2.11-1ubuntu1.4

Affected versions

3:4.*

3:4.2.4-1ubuntu2
3:4.2.8-1
3:4.2.9-1
3:4.2.11-1
3:4.2.11-1ubuntu1
3:4.2.11-1ubuntu1.1
3:4.2.11-1ubuntu1.2
3:4.2.11-1ubuntu1.3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "3:4.2.11-1ubuntu1.4",
            "binary_name": "python-django-doc"
        },
        {
            "binary_version": "3:4.2.11-1ubuntu1.4",
            "binary_name": "python3-django"
        }
    ]
}