{"schema_version":"1.7.3","id":"GHSA-xpfp-f569-q3p2","published":"2021-09-22T17:34:49Z","modified":"2025-02-21T05:30:56.014475Z","aliases":["BIT-django-2021-35042","CVE-2021-35042","PYSEC-2021-109"],"summary":"SQL Injection in Django","details":"Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.","affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2a1"},{"fixed":"3.2.5"}]}],"versions":["3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2a1","3.2b1","3.2rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-xpfp-f569-q3p2/GHSA-xpfp-f569-q3p2.json"}},{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0a1"},{"fixed":"3.1.13"}]}],"versions":["3.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.0a1","3.0b1","3.0rc1","3.1","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.1a1","3.1b1","3.1rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-xpfp-f569-q3p2/GHSA-xpfp-f569-q3p2.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35042"},{"type":"WEB","url":"https://github.com/django/django/commit/0bd57a879a0d54920bb9038a732645fb917040e9"},{"type":"WEB","url":"https://github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81f"},{"type":"WEB","url":"https://github.com/django/django/commit/dae83a24519d6f284c74414e0b81d64d9b5a0db4"},{"type":"WEB","url":"https://docs.djangoproject.com/en/3.2/releases/security"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xpfp-f569-q3p2"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-109.yaml"},{"type":"WEB","url":"https://groups.google.com/forum/#!forum/django-announce"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SS6NJTBYWOX6J7G4U3LUOILARJKWPQ5Y"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210805-0008"},{"type":"WEB","url":"https://www.djangoproject.com/weblog/2021/jul/01/security-releases"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2021/07/02/2"}],"database_specific":{"cwe_ids":["CWE-89"],"github_reviewed":true,"github_reviewed_at":"2021-07-03T00:06:31Z","nvd_published_at":"2021-07-02T10:15:00Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}