Skip to content

[Snyk:High] SQL Injection Django - due (03/27/2026) #6981

@pkfec

Description

@pkfec

Overview

Django is a high-level Python Web framework that encourages rapid development and clean, pragmatic design.

Affected versions of this package are vulnerable to SQL Injection via the band index parameter band_lhs in check_raster lookups when using PostGIS. An attacker can execute arbitrary SQL commands by supplying crafted input to this parameter.

https://app.snyk.io/vuln/SNYK-PYTHON-DJANGO-15183335

Security information

Factors contributing to the scoring:
Snyk: CVSS v4.0 7.7 - High Severity | CVSS v3.1 7.5 - High Severity
NVD: Not available. NVD has not yet published its analysis.
Why are the scores different? Learn how Snyk evaluates vulnerability scores

Action item:

  • Upgrade django to version 5.2.11 or 6.0.2

Completion criteria:

  • The Django package has been updated, and the Snyk vulnerability has been remediated.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    Status

    🗄️ PI backlog

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions