{ "id": "CVE-2024-42005", "sourceIdentifier": "cve@mitre.org", "published": "2024-08-07T15:15:56.220", "lastModified": "2024-08-07T15:17:46.717", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg." } ], "metrics": {}, "references": [ { "url": "https://docs.djangoproject.com/en/dev/releases/security/", "source": "cve@mitre.org" }, { "url": "https://groups.google.com/forum/#%21forum/django-announce", "source": "cve@mitre.org" }, { "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases/", "source": "cve@mitre.org" } ] }