[ubuntu/focal-security] python-django 2:2.2.12-1ubuntu0.25 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Tue Sep 3 16:44:44 UTC 2024


python-django (2:2.2.12-1ubuntu0.25) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-45230.patch: mitigate
      potential DoS in urlize and urlizetrunc template filters
      in django/utils/html.py,
      tests/template_tests/filter_tests/test_urlize.py,
      tests/utils_tests/test_html.py.
    - CVE-2024-45230
  * SECURITY UPDATE: User email enumeration
    - debian/patches/CVE-2024-45231.patch: avoid
      server error on password reset when email sending fails
      in django/contrib/auth/forms.py,
      tests/auth_tests/test_forms.py,
      tests/mail/custombackend.py.
    - CVE-2024-45231

Date: 2024-09-02 10:16:09.272455+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.25
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list