Executive brief
Django, a popular web framework, is vulnerable to a security flaw when used with Oracle databases. An attacker could exploit this to run unauthorized database commands, potentially leading to the theft of sensitive customer data or the modification of records. This issue specifically affects applications using geographic information system (GIS) features.
Technical details
A SQL injection vulnerability exists in Django's Oracle database backend. The root cause is improper neutralization of the 'tolerance' parameter within Geographic Information System (GIS) functions and aggregates. An attacker with low privileges can provide a specially crafted tolerance value to break out of SQL escaping and execute arbitrary SQL commands. This affects Django versions 1.11.x before 1.11.29, 2.2.x before 2.2.11, and 3.0.x before 3.0.4. Patches are available in versions 1.11.29, 2.2.11, and 3.0.4.
Affected products
- Django Django >= 1.11, < 1.11.29; >= 2.2, < 2.2.11; >= 3.0, < 3.0.4
Timeline
- 2020-03-04: advisory: Django security release announcement
- 2020-03-05: disclosed: NVD publication date
- 2020-06-05: other: GitHub Advisory Database publication