Back

HIGH

django: potential SQL injection via "tolerance" parameter in GIS functions and aggregates on Oracle

Published Mar 5, 2020

Description

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.

Affected products

Remediation

Red Hat statement

Although the following products ship the flawed code, they do not use or support its functionality and therefore will not be updated: * Red Hat OpenStack Platform * Red Hat Update Infrastructure 3 * Red Hat Ceph Storage The following products will be updated. However, because both products do not use the functionality, their Impact has been reduced to 'Low': * Red Hat Gluster Storage * Red Hat Satellite 6

Red Hat mitigation

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.

Weaknesses (1)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 5, 2020
Updated Aug 4, 2024
Reserved Feb 25, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 4, 2020
GHSA-3GH2-XW74-JMCW