mirror of
https://github.com/django/django.git
synced 2025-11-07 07:15:35 +00:00
Fixed CVE-2025-64459 -- Prevented SQL injections in Q/QuerySet via the _connector kwarg.
Thanks cyberstan for the report, Sarah Boyce, Adam Johnson, Simon Charette, and Jake Howard for the reviews.
This commit is contained in:
@@ -16,3 +16,10 @@ Windows. As a consequence, :class:`~django.http.HttpResponseRedirect`,
|
||||
:func:`redirect() <django.shortcuts.redirect>` were subject to a potential
|
||||
denial-of-service attack via certain inputs with a very large number of Unicode
|
||||
characters (follow up to :cve:`2025-27556`).
|
||||
|
||||
CVE-2025-64459: Potential SQL injection via ``_connector`` keyword argument
|
||||
===========================================================================
|
||||
|
||||
:meth:`.QuerySet.filter`, :meth:`~.QuerySet.exclude`, :meth:`~.QuerySet.get`,
|
||||
and :class:`~.Q` were subject to SQL injection using a suitably crafted
|
||||
dictionary, with dictionary expansion, as the ``_connector`` argument.
|
||||
|
||||
@@ -16,3 +16,10 @@ Windows. As a consequence, :class:`~django.http.HttpResponseRedirect`,
|
||||
:func:`redirect() <django.shortcuts.redirect>` were subject to a potential
|
||||
denial-of-service attack via certain inputs with a very large number of Unicode
|
||||
characters (follow up to :cve:`2025-27556`).
|
||||
|
||||
CVE-2025-64459: Potential SQL injection via ``_connector`` keyword argument
|
||||
===========================================================================
|
||||
|
||||
:meth:`.QuerySet.filter`, :meth:`~.QuerySet.exclude`, :meth:`~.QuerySet.get`,
|
||||
and :class:`~.Q` were subject to SQL injection using a suitably crafted
|
||||
dictionary, with dictionary expansion, as the ``_connector`` argument.
|
||||
|
||||
@@ -18,6 +18,13 @@ Windows. As a consequence, :class:`~django.http.HttpResponseRedirect`,
|
||||
denial-of-service attack via certain inputs with a very large number of Unicode
|
||||
characters (follow up to :cve:`2025-27556`).
|
||||
|
||||
CVE-2025-64459: Potential SQL injection via ``_connector`` keyword argument
|
||||
===========================================================================
|
||||
|
||||
:meth:`.QuerySet.filter`, :meth:`~.QuerySet.exclude`, :meth:`~.QuerySet.get`,
|
||||
and :class:`~.Q` were subject to SQL injection using a suitably crafted
|
||||
dictionary, with dictionary expansion, as the ``_connector`` argument.
|
||||
|
||||
Bugfixes
|
||||
========
|
||||
|
||||
|
||||
Reference in New Issue
Block a user