UbuntuUpdates.org

Package "python-django"

Name: python-django

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • High-level Python web development framework (documentation)
  • High-level Python web development framework

Latest version: 2:3.2.12-2ubuntu1.18
Release: jammy (22.04)
Level: security
Repository: main

Links



Other versions of "python-django" in Jammy

Repository Area Version
base main 2:3.2.12-2ubuntu1
updates main 2:3.2.12-2ubuntu1.18

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:3.2.12-2ubuntu1.18 2025-05-07 19:07:26 UTC

  python-django (2:3.2.12-2ubuntu1.18) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service in strip_tags()
    - debian/patches/CVE-2025-32873.patch: check tag depth in
      django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2025-32873

 -- Marc Deslauriers <email address hidden> Wed, 30 Apr 2025 10:34:27 -0400

Source diff to previous version

Version: 2:3.2.12-2ubuntu1.17 2025-03-06 23:07:36 UTC

  python-django (2:3.2.12-2ubuntu1.17) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service.
    - debian/patches/CVE-2025-26699.patch: Change wrap to use textwrap library
      in ./django/utils/text.py.
    - CVE-2025-26699
  * Fix FTBFS due to failing test (LP: #2100643)
    - debian/patches/0012-FTBFS-skip-failing-ip-test-arg.patch: Remove ip
      bracket argument from test.

 -- Hlib Korzhynskyy <email address hidden> Fri, 28 Feb 2025 12:59:44 -0330

Source diff to previous version
2100643 FTBFS on jammy due to python3.10 update
CVE-2025-26699 An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

Version: 2:3.2.12-2ubuntu1.16 2025-01-14 22:06:47 UTC

  python-django (2:3.2.12-2ubuntu1.16) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-56374.patch: mitigate potential
      DoS in IPv6 validation in django/db/models/fields/__init__.py.
      django/forms/fields.py, django/utils/ipv6.py,
      field_tests/test_genericipaddressfield.py,
      tests/utils_tests/test_ipv6.py.
    - CVE-2024-56374

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 08 Jan 2025 13:58:48 -0300

Source diff to previous version
CVE-2024-56374 An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, ...

Version: 2:3.2.12-2ubuntu1.15 2024-12-04 20:06:59 UTC

  python-django (2:3.2.12-2ubuntu1.15) jammy-security; urgency=medium

  * SECURITY UPDATE: Potential denial-of-service in
    django.utils.html.strip_tags()
    - debian/patches/CVE-2024-53907.patch: mitigated potential DoS in
      strip_tags() in django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2024-53907

 -- Marc Deslauriers <email address hidden> Wed, 27 Nov 2024 08:30:54 -0500

Source diff to previous version
CVE-2024-53907 Potential denial-of-service in django.utils.html.strip_tags()

Version: 2:3.2.12-2ubuntu1.14 2024-09-03 19:07:03 UTC

  python-django (2:3.2.12-2ubuntu1.14) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-45230.patch: mitigate
      potential DoS in urlize and urlizetrunc template filters
      in django/utils/html.py,
      tests/template_tests/filter_tests/test_urlize.py,
      tests/utils_tests/test_html.py.
    - CVE-2024-45230
  * SECURITY UPDATE: User email enumeration
    - debian/patches/CVE-2024-45231.patch: avoid
      server error on password reset when email sending fails
      in django/contrib/auth/forms.py,
      tests/auth_tests/test_forms.py,
      tests/mail/custombackend.py.
    - CVE-2024-45231

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 27 Aug 2024 11:53:08 -0300




About   -   Send Feedback to @ubuntu_updates