← Back to CVE List

CVE-2024-42005

Published: 2024-08-07T15:15Z
Last Modified: 2024-10-23T18:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt