Lucene search

K
osvGoogleOSV:USN-5373-2
HistoryApr 11, 2022 - 12:29 p.m.

python-django vulnerabilities

2022-04-1112:29:27
Google
osv.dev
4

10 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

USN-5373-1 fixed several vulnerabilities in Django. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that Django incorrectly handled certain certain column
aliases in the QuerySet.annotate(), aggregate(), and extra() methods. A
remote attacker could possibly use this issue to perform an SQL injection
attack. (CVE-2022-28346)

It was discovered that the Django URLValidator function incorrectly handled
newlines and tabs. A remote attacker could possibly use this issue to
perform a header injection attack. (CVE-2021-32052)