SQL injection in Django - CVE-2024-53908
Published: December 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within the django.db.models.fields.json.HasKey() function in Oracle lookup. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Gentoo Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Oracle Solaris
Storage Defender - Resiliency Service
Maximo Application Suite - Edge Data Collector
python-django (Ubuntu package)
python3-django (Ubuntu package)
python3.11-galaxy-importer (Red Hat package)
python3.11-yarl (Red Hat package)
python3.11-aiohappyeyeballs (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
automation-gateway (Red Hat package)
ansible-core (Red Hat package)
python3x-jinja2 (Red Hat package)
python-jinja2 (Red Hat package)
python3.11-aiodns (Red Hat package)
python3.11-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
python3.11-pulpcore (Red Hat package)
python311-Django
python3-Django
python-django
python-django-help
automation-controller (Red Hat package)
dev-python/django
Ansible Automation Platform
How to mitigate CVE-2024-53908
Storage Defender - Resiliency Service - update to 2.0.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.14, 9.0.6, 9.1.0
python-django (Ubuntu package) - update to Ubuntu Pro
python3-django (Ubuntu package) - addressed in versions Ubuntu Pro, 2:2.2.12-1ubuntu0.26, 2:3.2.12-2ubuntu1.15, 3:4.2.11-1ubuntu1.4, 3:4.2.15-1ubuntu1.1
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.27-1.el8ap, 0.4.27-1.el9ap
python3.11-yarl (Red Hat package) - addressed in versions 1.13.1-1.el8ap, 1.13.1-1.el9ap
Ansible Automation Platform - addressed in versions 2.4, 2.5
python3.11-aiohappyeyeballs (Red Hat package) - addressed in versions 2.4.4-1.el8ap, 2.4.4-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-9.el8ap, 2.4-9.el9ap, 2.5-7.el8ap, 2.5-7.el9ap
python3.11-django-ansible-base (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.14-2.el8ap, 2.16.14-2.el9ap
python3x-jinja2 (Red Hat package) - update to 3.1.5-1.el8ap
python-jinja2 (Red Hat package) - update to 3.1.5-1.el9ap
python3.11-aiodns (Red Hat package) - addressed in versions 3.2.0-1.el8ap, 3.2.0-1.el9ap
python3.11-aiohttp (Red Hat package) - addressed in versions 3.10.11-1.el8ap, 3.10.11-1.el9ap
python3x-pulpcore (Red Hat package) - update to 3.28.36-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.36-1.el9ap
python3.11-pulpcore (Red Hat package) - addressed in versions 3.49.29-1.el8ap, 3.49.29-1.el9ap
python311-Django - update to 4.2.11-150600.3.12.1
python3-Django - update to 4.2.15-3
python-django - update to 4.2.15-3
python-django-help - update to 4.2.15-3
automation-controller (Red Hat package) - addressed in versions 4.5.17-1.el8ap, 4.5.17-1.el9ap, 4.6.6-1.el8ap, 4.6.6-1.el9ap
dev-python/django - update to 5.2.1
Oracle Solaris - update to 11.4 SRU 77
External References
Related Security Bulletins
- Multiple vulnerabilities in Django
- Ubuntu update for python-django
- Ubuntu update for python-django
- SUSE update for python-Django
- openEuler 22.03 LTS SP1 update for python-django
- openEuler 22.03 LTS SP3 update for python-django
- openEuler 22.03 LTS SP4 update for python-django
- openEuler 24.03 LTS update for python-django
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Oracle Solaris update for third-party components
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Multiple vulnerabilities in IBM Edge Data Collector
- Gentoo update for Django