diff options
| author | Jacob Walls <jacobtylerwalls@gmail.com> | 2025-09-24 15:54:51 -0400 |
|---|---|---|
| committer | Natalia <124304+nessita@users.noreply.github.com> | 2025-11-05 09:53:18 -0300 |
| commit | 59ae82e67053d281ff4562a24bbba21299f0a7d4 (patch) | |
| tree | 88d61922dfc7eb686bbdbd91aee26e466e601c0c /tests | |
| parent | 770eea38d7a0e9ba9455140b5a9a9e33618226a7 (diff) | |
[4.2.x] Fixed CVE-2025-64459 -- Prevented SQL injections in Q/QuerySet via the _connector kwarg.
Thanks cyberstan for the report, Sarah Boyce, Adam Johnson, Simon
Charette, and Jake Howard for the reviews.
Backport of c880530ddd4fabd5939bab0e148bebe36699432a from main.
Diffstat (limited to 'tests')
| -rw-r--r-- | tests/queries/test_q.py | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/tests/queries/test_q.py b/tests/queries/test_q.py index cdf40292b0..5f20a41768 100644 --- a/tests/queries/test_q.py +++ b/tests/queries/test_q.py @@ -225,6 +225,11 @@ class QTests(SimpleTestCase): Q(*items, _connector=connector), ) + def test_connector_validation(self): + msg = f"_connector must be one of {Q.AND!r}, {Q.OR!r}, {Q.XOR!r}, or None." + with self.assertRaisesMessage(ValueError, msg): + Q(_connector="evil") + class QCheckTests(TestCase): def test_basic(self): |
