[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-53908":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":44,"aliases":45,"duplicate_of":9,"upstream":49,"downstream":50,"duplicates":71,"related":72,"reserved_at":9,"published_at":82,"modified_at":83,"state":84,"summary":85,"references_raw":94,"kevs":137,"epss":138,"epss_history":141,"metrics":405,"affected":417},"CVE-2024-53908","An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-89","Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.","weakness","Stable","Base","High",[20,24,28,32,36,40],{"id":21,"name":22,"techniques":23},"CAPEC-108","Command Line Execution through SQL Injection",[],{"id":25,"name":26,"techniques":27},"CAPEC-109","Object Relational Mapping Injection",[],{"id":29,"name":30,"techniques":31},"CAPEC-110","SQL Injection through SOAP Parameter Tampering",[],{"id":33,"name":34,"techniques":35},"CAPEC-470","Expanding Control over the Operating System from the Database",[],{"id":37,"name":38,"techniques":39},"CAPEC-66","SQL Injection",[],{"id":41,"name":42,"techniques":43},"CAPEC-7","Blind SQL Injection",[],[],[46,47,48],"GHSA-m9g8-fxxm-xg86","BIT-django-2024-53908","PYSEC-2024-157",[],[51,53,55,57,59,61,63,65,67,69],{"_key":52},"UBUNTU-CVE-2024-53908",{"_key":54},"SUSE-SU-2024:4285-1",{"_key":56},"OPENSUSE-SU-2024:14565-1",{"_key":58},"OPENSUSE-SU-2024:14568-1",{"_key":60},"OPENSUSE-SU-2026:10005-1",{"_key":62},"MGASA-2025-0039",{"_key":64},"USN-7136-1",{"_key":66},"DEBIAN-CVE-2024-53908",{"_key":68},"RHSA-2025:0340",{"_key":70},"RHSA-2025:0721",[],[73,74,75,76,77,78,80],{"_key":54},{"_key":56},{"_key":58},{"_key":60},{"_key":62},{"_key":79},"CGA-X7QQ-7CR6-XFQ4",{"_key":81},"CGA-HFR6-PMWX-XVVC","2024-12-06T00:00:00.000Z","2024-12-06T16:22:02.446Z","Analyzed",{"cisa_kev":86,"cisa_ransomware":86,"cisa_vendor":9,"epss_severity":87,"epss_score":88,"severity":89,"severity_score":90,"severity_version":91,"severity_source":92,"severity_vector":93,"severity_status":84},false,"low",0.00858,"critical",9.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[95,104,109,115,120,124,129,133],{"url":96,"sources":97,"tags":100},"https://docs.djangoproject.com/en/dev/releases/security/",[92,98,99],"nvd","osv_pypi",[101,102,103],"Patch","Vendor Advisory","WEB",{"url":105,"sources":106,"tags":107},"https://groups.google.com/g/django-announce",[92,98,99],[108,103],"Release Notes",{"url":110,"sources":111,"tags":112},"https://www.openwall.com/lists/oss-security/2024/12/04/3",[92,98,99],[113,114,103],"Mailing List","Third Party Advisory",{"url":116,"sources":117,"tags":118},"https://nvd.nist.gov/vuln/detail/CVE-2024-53908",[99],[119],"Advisory",{"url":121,"sources":122,"tags":123},"https://docs.djangoproject.com/en/dev/releases/security",[99],[103],{"url":125,"sources":126,"tags":127},"https://github.com/django/django",[99],[128],"PACKAGE",{"url":130,"sources":131,"tags":132},"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-157.yaml",[99],[103],{"url":134,"sources":135,"tags":136},"https://www.djangoproject.com/weblog/2024/dec/04/security-releases",[99],[103],[],{"date":139,"score":88,"percentile":140},"2026-06-04",0.75355,[142,146,149,152,155,157,160,163,166,169,172,175,177,180,183,187,190,193,196,198,201,204,207,210,213,216,218,221,225,228,231,234,236,238,241,243,246,249,252,255,258,260,263,266,269,272,275,278,281,284,286,289,292,295,298,301,303,306,309,312,315,318,321,324,327,330,333,336,339,341,345,347,350,353,356,359,363,366,369,372,375,378,381,384,387,390,393,395,398,401],{"date":143,"score":144,"percentile":145},"2025-11-04",0.00673,0.70587,{"date":147,"score":144,"percentile":148},"2025-11-05",0.70572,{"date":150,"score":144,"percentile":151},"2025-11-06",0.7057,{"date":153,"score":144,"percentile":154},"2025-11-07",0.70585,{"date":156,"score":144,"percentile":145},"2025-11-08",{"date":158,"score":144,"percentile":159},"2025-11-09",0.70579,{"date":161,"score":144,"percentile":162},"2025-11-10",0.70565,{"date":164,"score":144,"percentile":165},"2025-11-11",0.70573,{"date":167,"score":144,"percentile":168},"2025-11-12",0.70595,{"date":170,"score":144,"percentile":171},"2025-11-13",0.70603,{"date":173,"score":144,"percentile":174},"2025-11-14",0.70611,{"date":176,"score":144,"percentile":174},"2025-11-15",{"date":178,"score":144,"percentile":179},"2025-11-16",0.70606,{"date":181,"score":144,"percentile":182},"2025-11-17",0.706,{"date":184,"score":185,"percentile":186},"2025-11-18",0.03254,0.85902,{"date":188,"score":185,"percentile":189},"2025-11-19",0.85904,{"date":191,"score":185,"percentile":192},"2025-11-20",0.85905,{"date":194,"score":144,"percentile":195},"2025-11-21",0.70621,{"date":197,"score":144,"percentile":174},"2025-11-22",{"date":199,"score":144,"percentile":200},"2025-11-23",0.70592,{"date":202,"score":144,"percentile":203},"2025-11-24",0.70586,{"date":205,"score":144,"percentile":206},"2025-11-25",0.70589,{"date":208,"score":144,"percentile":209},"2025-11-26",0.70594,{"date":211,"score":144,"percentile":212},"2025-11-27",0.70593,{"date":214,"score":144,"percentile":215},"2025-11-28",0.70582,{"date":217,"score":144,"percentile":151},"2025-11-29",{"date":219,"score":144,"percentile":220},"2025-11-30",0.70563,{"date":222,"score":223,"percentile":224},"2025-12-01",0.00366,0.57962,{"date":226,"score":223,"percentile":227},"2025-12-02",0.57977,{"date":229,"score":223,"percentile":230},"2025-12-03",0.57974,{"date":232,"score":144,"percentile":233},"2025-12-04",0.70569,{"date":235,"score":144,"percentile":215},"2025-12-05",{"date":237,"score":144,"percentile":154},"2025-12-06",{"date":239,"score":144,"percentile":240},"2025-12-07",0.70584,{"date":242,"score":144,"percentile":206},"2025-12-08",{"date":244,"score":144,"percentile":245},"2025-12-09",0.7062,{"date":247,"score":144,"percentile":248},"2025-12-10",0.70656,{"date":250,"score":144,"percentile":251},"2025-12-11",0.70677,{"date":253,"score":144,"percentile":254},"2025-12-12",0.70703,{"date":256,"score":144,"percentile":257},"2025-12-13",0.70704,{"date":259,"score":144,"percentile":257},"2025-12-14",{"date":261,"score":144,"percentile":262},"2025-12-15",0.707,{"date":264,"score":144,"percentile":265},"2025-12-16",0.70708,{"date":267,"score":144,"percentile":268},"2025-12-17",0.70724,{"date":270,"score":144,"percentile":271},"2025-12-18",0.70749,{"date":273,"score":144,"percentile":274},"2025-12-19",0.70764,{"date":276,"score":144,"percentile":277},"2025-12-20",0.70762,{"date":279,"score":144,"percentile":280},"2025-12-21",0.70757,{"date":282,"score":144,"percentile":283},"2025-12-22",0.70756,{"date":285,"score":144,"percentile":283},"2025-12-23",{"date":287,"score":144,"percentile":288},"2025-12-24",0.70765,{"date":290,"score":144,"percentile":291},"2025-12-25",0.7079,{"date":293,"score":144,"percentile":294},"2025-12-26",0.70791,{"date":296,"score":144,"percentile":297},"2025-12-27",0.7083,{"date":299,"score":144,"percentile":300},"2025-12-28",0.70761,{"date":302,"score":144,"percentile":280},"2025-12-29",{"date":304,"score":144,"percentile":305},"2025-12-30",0.70773,{"date":307,"score":144,"percentile":308},"2025-12-31",0.70795,{"date":310,"score":223,"percentile":311},"2026-01-01",0.58197,{"date":313,"score":223,"percentile":314},"2026-01-02",0.58179,{"date":316,"score":223,"percentile":317},"2026-01-03",0.58175,{"date":319,"score":144,"percentile":320},"2026-01-04",0.70796,{"date":322,"score":144,"percentile":323},"2026-01-05",0.70789,{"date":325,"score":144,"percentile":326},"2026-01-06",0.70794,{"date":328,"score":144,"percentile":329},"2026-01-07",0.7081,{"date":331,"score":144,"percentile":332},"2026-01-08",0.70829,{"date":334,"score":144,"percentile":335},"2026-01-09",0.70837,{"date":337,"score":144,"percentile":338},"2026-01-10",0.70834,{"date":340,"score":144,"percentile":332},"2026-01-11",{"date":342,"score":343,"percentile":344},"2026-01-12",0.00687,0.71178,{"date":346,"score":343,"percentile":344},"2026-01-13",{"date":348,"score":343,"percentile":349},"2026-01-14",0.71201,{"date":351,"score":343,"percentile":352},"2026-01-15",0.71205,{"date":354,"score":343,"percentile":355},"2026-01-16",0.71221,{"date":357,"score":343,"percentile":358},"2026-01-17",0.71215,{"date":360,"score":361,"percentile":362},"2026-01-18",0.00706,0.71642,{"date":364,"score":361,"percentile":365},"2026-01-19",0.71636,{"date":367,"score":361,"percentile":368},"2026-01-20",0.71644,{"date":370,"score":361,"percentile":371},"2026-01-21",0.71648,{"date":373,"score":361,"percentile":374},"2026-01-22",0.71659,{"date":376,"score":361,"percentile":377},"2026-01-23",0.71689,{"date":379,"score":361,"percentile":380},"2026-01-24",0.71695,{"date":382,"score":361,"percentile":383},"2026-01-25",0.71673,{"date":385,"score":343,"percentile":386},"2026-01-26",0.71213,{"date":388,"score":343,"percentile":389},"2026-01-27",0.71214,{"date":391,"score":343,"percentile":392},"2026-01-28",0.71234,{"date":394,"score":343,"percentile":392},"2026-01-29",{"date":396,"score":343,"percentile":397},"2026-01-30",0.71241,{"date":399,"score":343,"percentile":400},"2026-01-31",0.71244,{"date":402,"score":403,"percentile":404},"2026-02-01",0.00504,0.6576,[406,410,412],{"source":92,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":407,"cvss_v4_0":9},{"baseScore":90,"baseSeverity":408,"vectorString":93,"impactScore":90,"exploitabilityScore":409},"CRITICAL",10,{"source":98,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":411,"cvss_v4_0":9},{"baseScore":90,"baseSeverity":408,"vectorString":93,"impactScore":90,"exploitabilityScore":409},{"source":99,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":413,"cvss_v4_0":414},{"baseScore":90,"baseSeverity":9,"vectorString":93,"impactScore":90,"exploitabilityScore":409},{"baseScore":415,"baseSeverity":9,"vectorString":416,"impactScore":9,"exploitabilityScore":9},9.2,"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U",[418,440],{"ecosystem":9,"name":419,"vendor":420,"product":421,"cpe_part":422,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":423},"Django","djangoproject","django","a",[424,432,436],{"version":425,"is_range":426,"range_type":427,"version_start":428,"version_start_type":429,"version_end":430,"version_end_type":431,"fixed_in":9},"gte4.2_lt4.2.17",true,"cpe","4.2","including","4.2.17","excluding",{"version":433,"is_range":426,"range_type":427,"version_start":434,"version_start_type":429,"version_end":435,"version_end_type":431,"fixed_in":9},"gte5.0_lt5.0.10","5.0","5.0.10",{"version":437,"is_range":426,"range_type":427,"version_start":438,"version_start_type":429,"version_end":439,"version_end_type":431,"fixed_in":9},"gte5.1_lt5.1.4","5.1","5.1.4",{"ecosystem":441,"name":421,"vendor":441,"product":421,"cpe_part":9,"purl_type":442,"purl_namespace":9,"purl_name":421,"source":9,"versions":443},"PyPI","pypi",[444,448,451,454,456,458],{"version":445,"is_range":426,"range_type":446,"version_start":447,"version_start_type":429,"version_end":435,"version_end_type":431,"fixed_in":9},"gte5_0_0_lt5_0_10","ecosystem","5.0.0",{"version":449,"is_range":426,"range_type":446,"version_start":450,"version_start_type":429,"version_end":439,"version_end_type":431,"fixed_in":9},"gte5_1_0_lt5_1_4","5.1.0",{"version":452,"is_range":426,"range_type":446,"version_start":453,"version_start_type":429,"version_end":430,"version_end_type":431,"fixed_in":9},"gte4_2_0_lt4_2_17","4.2.0",{"version":455,"is_range":426,"range_type":446,"version_start":438,"version_start_type":429,"version_end":439,"version_end_type":431,"fixed_in":9},"gte5_1_lt5_1_4",{"version":457,"is_range":426,"range_type":446,"version_start":434,"version_start_type":429,"version_end":435,"version_end_type":431,"fixed_in":9},"gte5_0_lt5_0_10",{"version":459,"is_range":426,"range_type":446,"version_start":428,"version_start_type":429,"version_end":430,"version_end_type":431,"fixed_in":9},"gte4_2_lt4_2_17"]