CVE-2022-28346
Last modified
CVE-2022-28346 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.. EPSS estimates a 18.40% chance of exploitation in the next 30 days.
Description
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Djangoproject | Django | >= 2.2, < 2.2.28 |
| Djangoproject | Django | >= 3.2, < 3.2.13 |
| Djangoproject | Django | >= 4.0, < 4.0.4 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 11.0 |
References
- http://www.openwall.com/lists/oss-security/2022/04/11/1Mailing List, Patch, Third Party Advisory
- https://docs.djangoproject.com/en/4.0/releases/security/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/04/msg00013.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5254Third Party Advisory
- https://www.djangoproject.com/weblog/2022/apr/11/security-releases/Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/04/11/1Mailing List, Patch, Third Party Advisory
- https://docs.djangoproject.com/en/4.0/releases/security/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/04/msg00013.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220609-0002/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5254Third Party Advisory
- https://www.djangoproject.com/weblog/2022/apr/11/security-releases/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28346?
How severe is CVE-2022-28346?
How do I fix CVE-2022-28346?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2833Endless Infinite loop in Blender-thumnailing due to logical …7.5
- CVE-2022-28330Apache HTTP Server 2.4.53 and earlier on Windows may read be…5.3
- CVE-2022-28331On Windows, Apache Portable Runtime 1.7.0 and earlier may wr…9.8
- CVE-2022-28339Trend Micro HouseCall for Home Networks version 5.3.1302 and…7.8
- CVE-2022-2834The Helpful WordPress plugin before 4.5.26 puts the exported…5.3
- CVE-2022-28345The Signal app before 5.34 for iOS allows URI spoofing via R…7.5
- CVE-2022-28347A SQL injection issue was discovered in QuerySet.explain() i…9.8
- CVE-2022-28348Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifr…9.8
- CVE-2022-28349Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28…9.8
- CVE-2022-2835A flaw was found in coreDNS. This flaw allows a malicious us…4.4
- CVE-2022-28350Arm Mali GPU Kernel Driver allows improper GPU operations in…9.8
- CVE-2022-28352WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 b…4.8
Are you affected by CVE-2022-28346?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
