-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4301-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb September 15, 2025 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : python-django Version : 2:2.2.28-1~deb11u8 CVE ID : CVE-2025-57833 Debian Bug : 1113865 It was discovered that there was a potential SQL injection attack in Django, a popular Python-based web development framework. Specifically, the FilteredRelation class was vulnerable to an SQL injection through its use of column aliases. This could have been exploited using a suitably crafted dictionary that was controlled by an attacker, either with dictionary expansion via the **kwargs passed to QuerySet.annotate() or by using QuerySet.alias() directly. For Debian 11 bullseye, this problem has been fixed in version 2:2.2.28-1~deb11u8. We recommend that you upgrade your python-django packages. For the detailed security status of python-django please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-django Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmjIkX4ACgkQHpU+J9Qx HliGzw/9HzkcMDPwUDLGPoaKM4eJFHnNcRHiZvQO7vDyI9u4N1xSwCWBnmeihDT5 MvZPxsbpcPkmxUawMmSuy6MbY+tLNsFGM5up9chxHqP3ceTMP0JLoaqZrGW+CFs1 mb98uN6jQXADBtE+6MRMLnEt+RzsaDnyw7OZ/4LJ2NbRImA8Pt8c9zU1CwV0ybOq M9tkApoEAH7db2XNXgyjFO+rA+u152r9Kwn5tENuqMglaL0uKhxWDuAvjGPLMqLH Il6i9T26inmLbV68M9RyJ0EuoDKLCikgN9qUL8o0irZBnUPh9+mE7g/euLVr/zn3 nAHDeN59bT+DrFsqBl0TZIT46u5b7/JSyR5knBfqrU8IQx9pvr8qbORbKx44TPya LpDYqeTKU6rXQdk5ket4vCwm1FvC48RvsviTXA517T3IqHMfNqSYdaucOUOs24FH z2AJr5Dh0DhbpBibdnGytndfWVuHMqBCrykVy3DN34QQPQUC179D+3CFLUTwjQAW /5z/baastijRTboHaf6DAWzZGIkgjN67ed38nu9L8jeD+FsNHbmeg5aAVIFZd2vh ZCWUC5CuWUCm/iCFz7tJ7yA+fanayljG/o8CK7zhH6Y8HQkhZ3JFftjGNTXOpGOd zo+KprWeMIXeye1cKyCZKU6hLr2CIqIb3+4/wtj2MP1CWtpdJjA= =Vxy5 -----END PGP SIGNATURE-----