[ubuntu/noble-security] python-django 3:4.2.11-1ubuntu1.3 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Tue Sep 3 16:44:42 UTC 2024


python-django (3:4.2.11-1ubuntu1.3) noble-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-45230.patch: mitigate
      potential DoS in urlize and urlizetrunc template filters
      in django/utils/html.py,
      tests/template_tests/filter_tests/test_urlize.py,
      tests/utils_tests/test_html.py.
    - CVE-2024-45230
  * SECURITY UPDATE: User email enumeration
    - debian/patches/CVE-2024-45231.patch: avoid
      server error on password reset when email sending fails
      in django/contrib/auth/forms.py,
      tests/auth_tests/test_forms.py,
      tests/mail/custombackend.py.
    - CVE-2024-45231

Date: 2024-08-30 12:44:09.577166+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/python-django/3:4.2.11-1ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list