python-django: Potential SQL injection in QuerySet.values() and values_list()
Published Aug 7, 2024
9.3
CRITICALCVSS 4.0
EPSS 1.50%
Description
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.
Affected products
No data.
- ≥ 4.2 · < 4.2.15
- ≥ 5.0 · < 5.0.8
-
- Version 4.2StatusaffectedConstraints<4.2.15
- Version 5.0StatusaffectedConstraints<5.0.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Djangoproject | Django | n/a |
|
Discovery 1 for RHEL 9
discovery/discovery-server-rhel9:1.12.0-1
Fixed · RHSA-2025:1249
Discovery 1 for RHEL 9
discovery/discovery-ui-rhel9:1.12.0-1
Fixed · RHSA-2025:1249
RHUI 4 for RHEL 8
python-django-0:4.2.15-1.el8ui
Fixed · RHSA-2025:1335
Red Hat Ansible Automation Platform 2.4 for RHEL 8
automation-controller-0:4.5.10-1.el8ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 8
python3x-django-0:4.2.15-1.el8ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 9
automation-controller-0:4.5.10-1.el9ap
Fixed · RHSA-2024:6428
Red Hat Ansible Automation Platform 2.4 for RHEL 9
python-django-0:4.2.15-1.el9ap
Fixed · RHSA-2024:6428
Red Hat Satellite 6.16 for RHEL 8
python-django-0:4.2.16-1.el8pc
Fixed · RHSA-2024:8906
Red Hat Satellite 6.16 for RHEL 8
python-django-0:4.2.16-1.el8pc
Fixed · RHSA-2024:8906
Red Hat Satellite 6.16 for RHEL 9
python-django-0:4.2.16-1.el9pc
Fixed · RHSA-2024:8906
Red Hat Satellite 6.16 for RHEL 9
python-django-0:4.2.16-1.el9pc
Fixed · RHSA-2024:8906
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/ee-dellemc-openmanage-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/platform-resource-runner-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Affected
Red Hat Ansible Automation Platform 2
python3.11-django
Affected
Red Hat Certification Program for Red Hat Enterprise Linux 9
redhat-certification
Fix deferred
Red Hat Certification for Red Hat Enterprise Linux 8
redhat-certification
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Discovery 1 for RHEL 9 | discovery/discovery-server-rhel9:1.12.0-1 | Fixed | RHSA-2025:1249 |
| Discovery 1 for RHEL 9 | discovery/discovery-ui-rhel9:1.12.0-1 | Fixed | RHSA-2025:1249 |
| RHUI 4 for RHEL 8 | python-django-0:4.2.15-1.el8ui | Fixed | RHSA-2025:1335 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | automation-controller-0:4.5.10-1.el8ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | python3x-django-0:4.2.15-1.el8ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | automation-controller-0:4.5.10-1.el9ap | Fixed | RHSA-2024:6428 |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | python-django-0:4.2.15-1.el9ap | Fixed | RHSA-2024:6428 |
| Red Hat Satellite 6.16 for RHEL 8 | python-django-0:4.2.16-1.el8pc | Fixed | RHSA-2024:8906 |
| Red Hat Satellite 6.16 for RHEL 8 | python-django-0:4.2.16-1.el8pc | Fixed | RHSA-2024:8906 |
| Red Hat Satellite 6.16 for RHEL 9 | python-django-0:4.2.16-1.el9pc | Fixed | RHSA-2024:8906 |
| Red Hat Satellite 6.16 for RHEL 9 | python-django-0:4.2.16-1.el9pc | Fixed | RHSA-2024:8906 |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/ee-dellemc-openmanage-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/platform-resource-runner-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Affected | n/a |
| Red Hat Ansible Automation Platform 2 | python3.11-django | Affected | n/a |
| Red Hat Certification Program for Red Hat Enterprise Linux 9 | redhat-certification | Fix deferred | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is considered of moderate severity rather than high or critical because it requires specific conditions to be exploitable. The potential for SQL injection exists only when QuerySet.values() or values_list() methods are used on models with a JSONField, and an attacker must have control over the JSON object keys passed as arguments. In typical use cases, these methods are often used with predefined or controlled data, limiting the attack surface. Furthermore, the impact is constrained to the manipulation of column aliases, rather than direct injection into more critical parts of the SQL query, reducing the overall risk compared to more direct forms of SQL injection vulnerabilities.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
2 other sources (CISA ADP, GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Aug 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.50% (0.01503) | 73.43th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.23% (0.01227) | 64.83th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.13% (0.00133) | 33.72th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.70% (0.01699) | 80.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.32% (0.00315) | 52.41th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00052) | 22.37th | v3 (v2023.03.01) |
| Aug 13, 2024 | 0.07% (0.00068) | 30.55th | v3 (v2023.03.01) |
References (12)
- https://access.redhat.com/security/cve/CVE-2024-42005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302436 Issue Tracking
- https://docs.djangoproject.com/en/dev/releases/security PatchVendor Advisory
- https://github.com/advisories/GHSA-pv4p-cwwg-4rph Advisory
- https://github.com/django/django/commit/32ebcbf2e1fe3e5ba79a6554a167efce81f7422d
- https://github.com/django/django/commit/f4af67b9b41e0f4c117a8741da3abbd1c869ab28
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-70.yaml
- https://groups.google.com/forum/#%21forum/django-announce Not Applicable
- https://nvd.nist.gov/vuln/detail/CVE-2024-42005
- https://security.netapp.com/advisory/ntap-20240905-0007
- https://www.cve.org/CVERecord?id=CVE-2024-42005
- https://www.djangoproject.com/weblog/2024/aug/06/security-releases Vendor Advisory
Change history (0)
No recorded changes yet.