Oval Definition:oval:com.ubuntu.disco:def:2019142340000000
Revision Date:2019-08-09Version:1
Title:CVE-2019-14234 on Ubuntu 19.04 (disco) - medium.
Description:An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-14234
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND python-django package in disco was vulnerable but has been fixed (note: '1:1.11.20-1ubuntu0.2').
  • BACK