CVE-2022-28346General(debian / debian_linux)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • django

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
debian_linuxdjango

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-30: 203-30
Signal classification1 categories
General
2100.0%
Full discourse2 posts
  • def name(*david, **kwast):@kwast
    General

    @mis4nthr0pic @lumatechdev Não entendi. Quem está usando Django 2.2 como no caso do CVE-2022-28346 ? Você juntou um monte de CVE da história do Django?

    Post summary

    The tweet merely asks who might be using Django 2.2 with reference to CVE-2022-28346, without providing any technical details, PoC, or evidence of exploitation.

    1000040
    329 followersView on X
  • Brother Alex@mis4nthr0pic
    General

    @kwast @lumatechdev erro gravíssimo 1. CVE-2013-1443 2. CVE-2019-6975 3. CVE-2021-33203 4. CVE-2022-28346 5. CVE-2016-7401

    Post summary

    The tweet merely lists several CVE identifiers without providing any additional context, details, or actionable information.

    1000048
    1.8K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSdebiandebian_linux9.0--
Appdjangoprojectdjango---

Explore more