django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle
Published Mar 5, 2020
8.7
HIGHCVSS 4.0
EPSS 22.51%
Description
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
Affected products
No data.
Configuration 1
- ≥ 1.11 · < 1.11.29
- ≥ 2.2 · < 2.2.11
- ≥ 3.0 · < 3.0.4
Configuration 2
- 9.0
- 10.0
Configuration 3
- 31
- 32
Configuration 4
- n/a
Configuration 5
- 16.04
- 18.04
- 19.10
No data.
Red Hat Satellite 6.9 for RHEL 7
pulp-0:2.21.5-2.el7sat
Fixed · RHSA-2021:1313
Red Hat Satellite 6.9 for RHEL 7
pulp-0:2.21.5-2.el7sat
Fixed · RHSA-2021:1313
Red Hat Satellite 6.9 for RHEL 7
python-django-0:1.11.29-1.el7sat
Fixed · RHSA-2021:1313
Red Hat Satellite 6.9 for RHEL 7
python-django-0:1.11.29-1.el7sat
Fixed · RHSA-2021:1313
Red Hat Ceph Storage 2
python-django
Will not fix
Red Hat Ceph Storage 3
python-django
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-django
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-django
Will not fix
Red Hat OpenStack Platform 15 (Stein)
python-django
Will not fix
Red Hat OpenStack Platform 16 (Train)
python-django
Will not fix
Red Hat Storage 3
python-django
Fix deferred
Red Hat Update Infrastructure 3 for Cloud Providers
python-django
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.9 for RHEL 7 | pulp-0:2.21.5-2.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Satellite 6.9 for RHEL 7 | pulp-0:2.21.5-2.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Satellite 6.9 for RHEL 7 | python-django-0:1.11.29-1.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Satellite 6.9 for RHEL 7 | python-django-0:1.11.29-1.el7sat | Fixed | RHSA-2021:1313 |
| Red Hat Ceph Storage 2 | python-django | Will not fix | n/a |
| Red Hat Ceph Storage 3 | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | python-django | Will not fix | n/a |
| Red Hat OpenStack Platform 16 (Train) | python-django | Will not fix | n/a |
| Red Hat Storage 3 | python-django | Fix deferred | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-django | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Although the following products ship the flawed code, they do not use or support its functionality and therefore will not be updated: * Red Hat OpenStack Platform * Red Hat Update Infrastructure 3 * Red Hat Ceph Storage The following products will be updated. However, because both products do not use the functionality, their Impact has been reduced to 'Low': * Red Hat Gluster Storage * Red Hat Satellite 6
Red Hat mitigation
There is no known mitigation for this issue, the flaw can only be resolved by applying updates.
References (21)
- https://access.redhat.com/security/cve/CVE-2020-9402 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1810088 Issue Tracking
- https://docs.djangoproject.com/en/3.0/releases/security x_refsource_MISCPatchRelease NotesVendor Advisory
- https://github.com/advisories/GHSA-3gh2-xw74-jmcw Advisory
- https://github.com/django/django/commit/6695d29b1c1ce979725816295a26ecc64ae0e927
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2020-345.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2020-36.yaml
- https://groups.google.com/forum/#!topic/django-announce/fLUh_pOaKrY
- https://groups.google.com/forum/#%21topic/django-announce/fLUh_pOaKrY x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2022/05/msg00035.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T6MINDUUMZ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UZMN2NKAGTFE3YKMNM2JVJG7R2W7LLHY vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T6MINDUUMZ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UZMN2NKAGTFE3YKMNM2JVJG7R2W7LLHY
- https://nvd.nist.gov/vuln/detail/CVE-2020-9402
- https://security.gentoo.org/glsa/202004-17 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200327-0004 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4296-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9402
- https://www.debian.org/security/2020/dsa-4705 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.djangoproject.com/weblog/2020/mar/04/security-releases x_refsource_CONFIRMPatchVendor Advisory
Change history (0)
No recorded changes yet.