Critical severity9.8NVD Advisory· Published Jul 2, 2021· Updated Jun 17, 2026
CVE-2021-35042
CVE-2021-35042
Description
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DjangoPyPI | >= 3.2a1, < 3.2.5 | 3.2.5 |
DjangoPyPI | >= 3.0a1, < 3.1.13 | 3.1.13 |
Affected products
9- Django/Djangodescription
- ghsa-coords6 versionspkg:pypi/djangopkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:bitnami/djangopkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweed
>= 3.2a1, < 3.2.5+ 5 more
- (no CPE)range: >= 3.2a1, < 3.2.5
- (no CPE)range: < 3.2.7-2.3
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: >= 3.1.0, < 3.1.13
- (no CPE)range: < 4.2.14-1.1
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
17- docs.djangoproject.com/en/3.2/releases/security/nvdPatchVendor Advisory
- www.djangoproject.com/weblog/2021/jul/01/security-releases/nvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2021/07/02/2nvdMailing ListPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-xpfp-f569-q3p2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-35042ghsaADVISORY
- security.netapp.com/advisory/ntap-20210805-0008/nvdThird Party Advisory
- docs.djangoproject.com/en/3.2/releases/securityghsaWEB
- github.com/django/django/commit/0bd57a879a0d54920bb9038a732645fb917040e9ghsaWEB
- github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81fghsaWEB
- github.com/django/django/commit/dae83a24519d6f284c74414e0b81d64d9b5a0db4ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-109.yamlghsaWEB
- groups.google.com/forum/ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/SS6NJTBYWOX6J7G4U3LUOILARJKWPQ5YghsaWEB
- security.netapp.com/advisory/ntap-20210805-0008ghsaWEB
- www.djangoproject.com/weblog/2021/jul/01/security-releasesghsaWEB
- groups.google.com/forum/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SS6NJTBYWOX6J7G4U3LUOILARJKWPQ5Y/nvd
News mentions
0No linked articles in our index yet.