---
title: "Note di rilascio di Django 2.2.28"
version: 5.2
locale: it
source: https://docs.djangoproject.com/it/5.2/releases/2.2.28/
canonical: https://djangodocs.dev/it/5.2/releases/2.2.28/
---
# Note di rilascio di Django 2.2.28

*11 Aprile 2022*

Django 2.2.28 fixes two security issues with severity «high» in 2.2.27.

## CVE-2022-28346: Potential SQL injection in `QuerySet.annotate()`, `aggregate()`, and `extra()`

[`QuerySet.annotate()`](/it/5.2/ref/models/querysets/#django.db.models.query.QuerySet.annotate), [`aggregate()`](/it/5.2/ref/models/querysets/#django.db.models.query.QuerySet.aggregate), and
[`extra()`](/it/5.2/ref/models/querysets/#django.db.models.query.QuerySet.extra) methods were subject to SQL injection in column
aliases, using a suitably crafted dictionary, with dictionary expansion, as the
`**kwargs` passed to these methods.

## CVE-2022-28347: Potential SQL injection via `QuerySet.explain(**options)` on PostgreSQL

[`QuerySet.explain()`](/it/5.2/ref/models/querysets/#django.db.models.query.QuerySet.explain) method was subject to SQL injection in option names,
using a suitably crafted dictionary, with dictionary expansion, as the
`**options` argument.
