Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "16.04"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "18.04"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "19.10"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "31"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"
},
{
"extracted_events": [
{
"last_affected": "32"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
}
]
}{
"extracted_events": [
{
"introduced": "1.11"
},
{
"fixed": "1.11.29"
},
{
"introduced": "2.2"
},
{
"fixed": "2.2.11"
},
{
"introduced": "3.0"
},
{
"fixed": "3.0.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*"
}