python-django 2:3.2.4-1 source package in Debian

Changelog

python-django (2:3.2.4-1) experimental; urgency=medium

  * New upstream security release. (Closes: #989394)

    - CVE-2021-33203: Potential directory traversal via admindocs

      Staff members could use the admindocs TemplateDetailView view to
      check the existence of arbitrary files. Additionally, if (and only
      if) the default admindocs templates have been customized by the
      developers to also expose the file contents, then not only the
      existence but also the file contents would have been exposed.

      As a mitigation, path sanitation is now applied and only files
      within the template root directories can be loaded.

      This issue has low severity, according to the Django security
      policy.

      Thanks to Rasmus Lerchedahl Petersen and Rasmus Wriedt Larsen from
      the CodeQL Python team for the report.

    - CVE-2021-33571: Possible indeterminate SSRF, RFI, and LFI attacks
      since validators accepted leading zeros in IPv4 addresses

      URLValidator, validate_ipv4_address(), and
      validate_ipv46_address() didn't prohibit leading zeros in octal
      literals. If you used such values you could suffer from
      indeterminate SSRF, RFI, and LFI attacks.

      validate_ipv4_address() and validate_ipv46_address() validators
      were not affected on Python 3.9.5+.

      This issue has medium severity, according to the Django security
      policy.

  * Bump Standards-Version to 4.5.1.

 -- Chris Lamb <email address hidden>  Wed, 02 Jun 2021 16:08:13 +0100

Upload details

Uploaded by:
Debian Python Team
Uploaded to:
Experimental
Original maintainer:
Debian Python Team
Architectures:
all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
python-django_3.2.4-1.dsc 2.7 KiB c045b9445260288da3d6f7277c021e7bb48c00a75cb7e99c847523b7a8d637e0
python-django_3.2.4.orig.tar.gz 9.4 MiB 66c9d8db8cc6fe938a28b7887c1596e42d522e27618562517cc8929eb7e7f296
python-django_3.2.4-1.debian.tar.xz 26.4 KiB db66b00bd8120de0d96702b9a7890d4705e9fddfc44cedddf3987d6ca45ff7c6

No changes file available.

Binary packages built by this source