Related Vulnerabilities: CVE-2019-14234  

Key and index lookups for JSONField and key lookups for HStoreField were subject to SQL injection, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to QuerySet.filter().

Severity Medium

Remote Yes

Type Sql injection

Description

Key and index lookups for JSONField and key lookups for HStoreField were subject to SQL injection, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to QuerySet.filter().

AVG-1015 python-django 2.2.3-1 Medium Vulnerable

AVG-1014 python2-django 1.11.22-1 Medium Vulnerable

https://github.com/django/django/commit/7deeabc7c7526786df6894429ce89a9c4b614086