UbuntuUpdates.org

Package "python3-django"

Name: python3-django

Description:

High-level Python web development framework

Latest version: 3:4.2.18-1ubuntu1.3
Release: plucky (25.04)
Level: updates
Repository: main
Head package: python-django
Homepage: http://www.djangoproject.com/

Links


Download "python3-django"


Other versions of "python3-django" in Plucky

Repository Area Version
base main 3:4.2.18-1ubuntu1
security main 3:4.2.18-1ubuntu1.3

Changelog

Version: 3:4.2.18-1ubuntu1.3 2025-06-16 18:07:46 UTC

  python-django (3:4.2.18-1ubuntu1.3) plucky-security; urgency=medium

  * SECURITY UPDATE: Prevented log injection
    - debian/patches/CVE-2025-48432-2.patch: prevented log injection in
      remaining response logging in django/views/generic/base.py,
      test/generic_views/test_base.py (LP: #2113924)

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 10 Jun 2025 16:08:26 -0300

Source diff to previous version
2113924 Incomplete fix for CVE-2025-48432
CVE-2025-48432 Potential log injection via unescaped request path

Version: 3:4.2.18-1ubuntu1.2 2025-06-04 23:07:12 UTC

  python-django (3:4.2.18-1ubuntu1.2) plucky-security; urgency=medium

  * SECURITY UPDATE: Log structure manipulation
    - debian/patches/CVE-2025-48432.patch: escape formatting
      arguments in log_response() in django/utils/log.py,
      tests/logging_tests/tests.py.
    - CVE-2025-48432

 -- Leonidas Da Silva Barbosa <email address hidden> Thu, 29 May 2025 13:08:34 -0300

Source diff to previous version
CVE-2025-48432 Potential log injection via unescaped request path

Version: 3:4.2.18-1ubuntu1.1 2025-05-07 20:07:20 UTC

  python-django (3:4.2.18-1ubuntu1.1) plucky-security; urgency=medium

  * SECURITY UPDATE: Denial of service in strip_tags()
    - debian/patches/CVE-2025-32873.patch: check tag depth in
      django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2025-32873

 -- Marc Deslauriers <email address hidden> Wed, 30 Apr 2025 10:30:41 -0400




About   -   Send Feedback to @ubuntu_updates