Description
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.
Remediation
References
Related Vulnerabilities
PHP Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2004-0594)
OpenSSL Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2023-5678)
WordPress Plugin Theme Tuner 'tt-abspath' Parameter Remote File Include (0.7)
Oracle Application Server Other Vulnerability (CVE-2007-2119)