1-day

CVE-2022-28347: Potential SQLi via QuerySet.explain() on PostgreSQL

CVE-2022-28347: Potential SQLi via QuerySet.explain() on PostgreSQL

CVE-2022-28347, Potential SQL injection in Django QuerySet explain() Analysis > https://github.com/advisories/GHSA-w24h-v9qh-8gxj ์ด ์ทจ์•ฝ์ ์€ PostgreSQL ํ™˜๊ฒฝ์—์„œ Django QuerySet์˜ explain ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•  ๋•Œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ SQL Injection ์ทจ์•ฝ์ ์ด๋‹ค. QuerySet ์˜ค๋ธŒ์ ํŠธ์˜ explain() ๋ฉ”์†Œ๋“œ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋ฉด EXPLAIN ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ MySQL๊ณผ PostgreSQL์—์„œ๋Š” ํŠน๋ณ„ํžˆ EXPLAIN ๋ช…๋ น์–ด์— ์˜ต์…˜์„ ์ง€์ •ํ• 
Seokchan Yoon
CVE-2022-34265: Potential SQLi via Trunc() and Extract()

CVE-2022-34265: Potential SQLi via Trunc() and Extract()

๊ฐœ์š” CVE-2022-34265: Potential SQL injection via Trunc(kind) and Extract(lookup_name) arguments ์ตœ๊ทผ ์šฐ๋ฆฌ ํšŒ์‚ฌ ์Šฌ๋ž™ ๋ฐฉ์—์„œ ํ‰์†Œ ์กด๊ฒฝํ•˜๋˜ ๊ฐ“ํ•ด์ปค ๋ถ„์ด ์˜ฌ๋ ค์ฃผ์‹  Django SQL Injection CVE๊ฐ€ ํ•˜๋‚˜ ์žˆ์–ด์„œ ๋ถ„์„ํ•ด๋ณด์•˜๋‹ค. ์•„๋ฌด๋ž˜๋„ Django๋ฅผ ํ†ตํ•ด ์‚ฌ๋‚ด ํ”„๋กœ์ ํŠธ, ํ•™๊ต ํ”„๋กœ์ ํŠธ๋ฅผ ๋ช‡ ๋ฒˆ์”ฉ ์ง„ํ–‰ํ•ด๋ณธ ๊ฒฝํ—˜์ด ์žˆ๋‹ค๋ณด๋‹ˆ ์ž์นญ Django ์ „๋ฌธ๊ฐ€๋กœ์„œ CVE๋ฅผ ๋ถ„์„ํ•ด๋ณด์ง€ ์•Š๊ณ  ์ง€๋‚˜์น  ์ˆ˜๊ฐ€
Seokchan Yoon