A vulnerability in the Django web framework that may lead to SQL code injection.

Correction releases for the Django web framework versions 4.0.6 and 3.2.14 have been published, addressing a vulnerability (CVE-2022-34265) that could potentially allow for SQL code injection. The issue affects applications that use unvalidated external data in the parameters kind and lookup_name, which are passed to the functions Trunc(kind) and Extract(lookup_name). Applications that only allow validated data in lookup_name and kind are not affected by this vulnerability.

The issue has been blocked by prohibiting the use of characters other than letters, digits, '-', '_', '(', and ')' in the arguments of the Extract and Trunc functions. Previously, single quotes were not trimmed from passed values, which allowed SQL constructs like "day' FROM start_datetime)) OR 1=1;--" and "year', start_datetime)) OR 1=1;--" to be executed. In the next release 4.1, additional security enhancements for date extraction and truncation methods are planned, though changes made to the API will lead to compatibility issues with third-party database backends.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster