django

Implementing Logging for Signing in, at django `graphene_jwt`

Implementing Logging for Signing in, at django `graphene_jwt`

๊ฐœ์š” 2020๋…„์— ์ง„ํ–‰ํ–ˆ๋˜ ํšŒ์‚ฌ ํ”„๋กœ์ ํŠธ ์ค‘์— Django์™€ GraphQL์„ ์‚ฌ์šฉํ•œ ํ”„๋กœ์ ํŠธ๊ฐ€ ์žˆ์—ˆ๋‹ค. ์‚ฌ์šฉ์ž์˜ ์ด์šฉ ๊ธฐ๋ก์„ ์ €์žฅํ•ด์•ผ ํ•  ํ•„์š”๊ฐ€ ์žˆ๋˜ ํ”„๋กœ์ ํŠธ๋ผ ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•˜๋Š” ๊ฒƒ์„ ํฌํ•จํ•ด์„œ ํ–‰์œ„๋ฅผ ๊ธฐ๋กํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ถ”๊ฐ€ํ•ด์•ผํ–ˆ๋‹ค. ๊ทผ๋ฐ ๋ˆ„๊ตฐ๊ฐ€ ๋งŒ๋“ค์–ด ๋‘” ํŒจํ‚ค์ง€์—๋Š” ๋กœ๊น… ๊ธฐ๋Šฅ์„ ๋ณ„๋„๋กœ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์€ ์—†์—ˆ๊ณ , ์ด๊ฒƒ์„ ์–ด๋–ป๊ฒŒ ํ•ด๊ฒฐํ–ˆ๋Š”์ง€ ๊ธฐ๋กํ•˜๋Š” ๊ธ€์ด๋‹ค. ๋ณธ๋ฌธ ๋น ๋ฅด๊ฒŒ ๊ฐœ๋ฐœํ•  ํ•„์š”๊ฐ€ ์žˆ๋˜
Seokchan Yoon
CVE-2022-28347: Potential SQLi via QuerySet.explain() on PostgreSQL

CVE-2022-28347: Potential SQLi via QuerySet.explain() on PostgreSQL

CVE-2022-28347, Potential SQL injection in Django QuerySet explain() Analysis > https://github.com/advisories/GHSA-w24h-v9qh-8gxj ์ด ์ทจ์•ฝ์ ์€ PostgreSQL ํ™˜๊ฒฝ์—์„œ Django QuerySet์˜ explain ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•  ๋•Œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ SQL Injection ์ทจ์•ฝ์ ์ด๋‹ค. QuerySet ์˜ค๋ธŒ์ ํŠธ์˜ explain() ๋ฉ”์†Œ๋“œ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋ฉด EXPLAIN ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ MySQL๊ณผ PostgreSQL์—์„œ๋Š” ํŠน๋ณ„ํžˆ EXPLAIN ๋ช…๋ น์–ด์— ์˜ต์…˜์„ ์ง€์ •ํ• 
Seokchan Yoon
CVE-2022-34265: Potential SQLi via Trunc() and Extract()

CVE-2022-34265: Potential SQLi via Trunc() and Extract()

๊ฐœ์š” CVE-2022-34265: Potential SQL injection via Trunc(kind) and Extract(lookup_name) arguments ์ตœ๊ทผ ์šฐ๋ฆฌ ํšŒ์‚ฌ ์Šฌ๋ž™ ๋ฐฉ์—์„œ ํ‰์†Œ ์กด๊ฒฝํ•˜๋˜ ๊ฐ“ํ•ด์ปค ๋ถ„์ด ์˜ฌ๋ ค์ฃผ์‹  Django SQL Injection CVE๊ฐ€ ํ•˜๋‚˜ ์žˆ์–ด์„œ ๋ถ„์„ํ•ด๋ณด์•˜๋‹ค. ์•„๋ฌด๋ž˜๋„ Django๋ฅผ ํ†ตํ•ด ์‚ฌ๋‚ด ํ”„๋กœ์ ํŠธ, ํ•™๊ต ํ”„๋กœ์ ํŠธ๋ฅผ ๋ช‡ ๋ฒˆ์”ฉ ์ง„ํ–‰ํ•ด๋ณธ ๊ฒฝํ—˜์ด ์žˆ๋‹ค๋ณด๋‹ˆ ์ž์นญ Django ์ „๋ฌธ๊ฐ€๋กœ์„œ CVE๋ฅผ ๋ถ„์„ํ•ด๋ณด์ง€ ์•Š๊ณ  ์ง€๋‚˜์น  ์ˆ˜๊ฐ€
Seokchan Yoon