ZeroHour

CVE-2020-9402

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
Modified
Description

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.

Vendors
djangoprojectdebianfedoraprojectnetappcanonical
Products
django, debian linux, fedora, steelstore cloud integrated storage, ubuntu linux
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.