CVE-2019-14234: Debian Linux

Critical severity, CVSS 9.8. EPSS: 47.7% chance of exploitation in the next 30 days.

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Djangoproject Django: from 1.11, before 1.11.23 (fixed in 1.11.23); from 2.1, before 2.1.11 (fixed in 2.1.11); from 2.2, before 2.2.4 (fixed in 2.2.4)
  • Fedoraproject Fedora: version 30 only

Published 2019-08-09. Last modified 2026-06-17.