Lucene search

K
redhatcveRedhat.comRH:CVE-2020-7471
HistoryFeb 05, 2020 - 2:33 p.m.

CVE-2020-7471

2020-02-0514:33:17
redhat.com
access.redhat.com
17

0.01 Low

EPSS

Percentile

84.0%

A flaw was found in Django, where it may allow SQL injection if improperly sanitized data is used as a StringAgg delimiter. If a suitably crafted delimiter is passed to a ‘contrib.postgres.aggregates.StringAgg’ instance, it is possible to break escaping and inject malicious SQL. An attacker could use this flaw to cause a denial of service, information disclosure, or privilege escalation.