An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
https://www.debian.org/security/2022/dsa-5254
https://github.com/muhammedalakbarli/cvault
https://github.com/CarterPerez-dev/angela
https://github.com/yanggangbb/CVE-Docker
https://github.com/yoryio/django-vuln-research
https://github.com/simonepetruzzi/WebSecurityProject
https://github.com/traumatising/CVE-2022-34265
https://github.com/not-xences/CVE-2022-34265
https://github.com/aeyesec/CVE-2022-34265
https://github.com/advisories/GHSA-p64x-8rxx-wf6q
https://www.djangoproject.com/weblog/2022/jul/04/security-releases/
Published: 2022-07-04
Updated: 2026-06-17
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.73274