-
Notifications
You must be signed in to change notification settings - Fork 43
Open
Labels
Security: highRemediate within 30 daysRemediate within 30 days
Milestone
Description
Overview
Django is a high-level Python Web framework that encourages rapid development and clean, pragmatic design.
Affected versions of this package are vulnerable to SQL Injection via the band index parameter band_lhs in check_raster lookups when using PostGIS. An attacker can execute arbitrary SQL commands by supplying crafted input to this parameter.
https://app.snyk.io/vuln/SNYK-PYTHON-DJANGO-15183335
Security information
Factors contributing to the scoring:
Snyk: CVSS v4.0 7.7 - High Severity | CVSS v3.1 7.5 - High Severity
NVD: Not available. NVD has not yet published its analysis.
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Action item:
- Upgrade django to version 5.2.11 or 6.0.2
Completion criteria:
- The Django package has been updated, and the Snyk vulnerability has been remediated.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Security: highRemediate within 30 daysRemediate within 30 days
Type
Projects
Status
🗄️ PI backlog