Django JSONField/HStoreField SQL×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-08-02

? Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-14234£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


Django Ö÷¿ª·¢·ÖÖ§

Django 2.2.x < 2.2.4
Django 2.1.x < 2.1.11

Django 1.11.x < 1.11.23


Îó²î¸ÅÊö


Django ÊÇÒ»¸ö¿ª·ÅÔ´´úÂëµÄWebÓ¦Óÿò¼Ü£¬£¬£¬ÓÉPythonд³É£¬£¬£¬ÏÖÔÚÊÇPython Web ¿ª·¢ÀïʹÓÃ×îÆÕ±éµÄ¿ò¼ÜÖ®Ò»¡£¡£¡£¡£¡£


8ÔÂ1ÈÕ£¬£¬£¬Django ¹Ù·½Ðû²¼¸üУ¬£¬£¬ÆäÖÐÐÞ¸´ÁËÒ»¸ö±£´æÓÚ¿ò¼ÜÖеÄSQL×¢ÈëÎó²îΣº¦£¨CVE-2019-14234£©¡£¡£¡£¡£¡£


µ±Ê¹ÓÃÓû§¿É¿ØµÄÊý¾Ý×÷Ϊ²ÎÊý£¬£¬£¬ÒÔ**kwargsµÄÐÎʽ´«ÈëQuerySet.filter()º¯Êý£¬£¬£¬¶Ôdjango.contrib.postgres.fields.JSONField¾ÙÐмü/Ë÷Òý²éÕÒ£¬£¬£¬»ò¶Ôdjango.contrib.postgres.fields.HStoreField¾ÙÐмü²éÕÒʱ£¬£¬£¬½«»áµ¼ÖÂSQL×¢Èë¡£¡£¡£¡£¡£ 


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬Çë¸üРDjango ÖÁÒÔ϶ÔÓ¦°æ±¾£º


Django 2.2.4
Django 2.1.11

Django 1.11.23


²Î¿¼Á´½Ó


https://www.djangoproject.com/weblog/2019/aug/01/security-releases/