[SECURITY] [DLA 4301-1] python-django security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4301-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
September 15, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : python-django
Version : 2:2.2.28-1~deb11u8
CVE ID : CVE-2025-57833
Debian Bug : 1113865
It was discovered that there was a potential SQL injection attack in
Django, a popular Python-based web development framework.
Specifically, the FilteredRelation class was vulnerable to an SQL
injection through its use of column aliases. This could have been
exploited using a suitably crafted dictionary that was controlled by
an attacker, either with dictionary expansion via the **kwargs passed
to QuerySet.annotate() or by using QuerySet.alias() directly.
For Debian 11 bullseye, this problem has been fixed in version
2:2.2.28-1~deb11u8.
We recommend that you upgrade your python-django packages.
For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-django
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmjIkX4ACgkQHpU+J9Qx
HliGzw/9HzkcMDPwUDLGPoaKM4eJFHnNcRHiZvQO7vDyI9u4N1xSwCWBnmeihDT5
MvZPxsbpcPkmxUawMmSuy6MbY+tLNsFGM5up9chxHqP3ceTMP0JLoaqZrGW+CFs1
mb98uN6jQXADBtE+6MRMLnEt+RzsaDnyw7OZ/4LJ2NbRImA8Pt8c9zU1CwV0ybOq
M9tkApoEAH7db2XNXgyjFO+rA+u152r9Kwn5tENuqMglaL0uKhxWDuAvjGPLMqLH
Il6i9T26inmLbV68M9RyJ0EuoDKLCikgN9qUL8o0irZBnUPh9+mE7g/euLVr/zn3
nAHDeN59bT+DrFsqBl0TZIT46u5b7/JSyR5knBfqrU8IQx9pvr8qbORbKx44TPya
LpDYqeTKU6rXQdk5ket4vCwm1FvC48RvsviTXA517T3IqHMfNqSYdaucOUOs24FH
z2AJr5Dh0DhbpBibdnGytndfWVuHMqBCrykVy3DN34QQPQUC179D+3CFLUTwjQAW
/5z/baastijRTboHaf6DAWzZGIkgjN67ed38nu9L8jeD+FsNHbmeg5aAVIFZd2vh
ZCWUC5CuWUCm/iCFz7tJ7yA+fanayljG/o8CK7zhH6Y8HQkhZ3JFftjGNTXOpGOd
zo+KprWeMIXeye1cKyCZKU6hLr2CIqIb3+4/wtj2MP1CWtpdJjA=
=Vxy5
-----END PGP SIGNATURE-----
Reply to: