Overview

Request 1146450 accepted

- Add CVE-2024-24680.patch (bsc#1219683, CVE-2024-24680)

- Add CVE-2023-43665.patch (bsc#1215978, CVE-2023-43665)
* Denial-of-service possibility in django.utils.text.Truncator

- Add CVE-2023-41164.patch (bsc#1214667, CVE-2023-41164)
* Potential denial of service vulnerability
in django.utils.encoding.uri_to_iri()

- Add CVE-2023-36053.patch (bsc#1212742, CVE-2023-36053)

- Add CVE-2023-24580-DOS_file_upload.patch (CVE-2023-24580,
bsc#1208082) to prevent DOS in file uploads.

- Rename Django-1.11.29.tar.gz.asc to Django-1.11.29.tar.gz.checksums.txt
to avoid source_validator incorrectly trying to use it as a detached
signature file for the sources tarball.
- Remove unnecessary project.diff file.

- Add CVE-2022-28346.patch (bsc#1198398, CVE-2022-28346)
* Potential SQL injection in QuerySet.annotate(),aggregate() and extra()
- Add CVE-2022-34265.patch (bsc#1201186, CVE-2022-34265)
* SQL injection via Trunc(kind) and Extract(lookup_name) arguments

- CVE-2021-45452.patch: added missing attribute to validate_file_name (bsc#1194116)

- Add CVE-2022-22818.patch (bsc#1195086, CVE-2022-22818)
* Possible XSS via ``{% debug %}`` template tag
- Add CVE-2022-23833.patch (bsc#1195088, CVE-2022-23833)
* Denial-of-service possibility in file uploads

Request History
Guang Yee's avatar

yeey created request

- Add CVE-2024-24680.patch (bsc#1219683, CVE-2024-24680)

- Add CVE-2023-43665.patch (bsc#1215978, CVE-2023-43665)
* Denial-of-service possibility in django.utils.text.Truncator

- Add CVE-2023-41164.patch (bsc#1214667, CVE-2023-41164)
* Potential denial of service vulnerability
in django.utils.encoding.uri_to_iri()

- Add CVE-2023-36053.patch (bsc#1212742, CVE-2023-36053)

- Add CVE-2023-24580-DOS_file_upload.patch (CVE-2023-24580,
bsc#1208082) to prevent DOS in file uploads.

- Rename Django-1.11.29.tar.gz.asc to Django-1.11.29.tar.gz.checksums.txt
to avoid source_validator incorrectly trying to use it as a detached
signature file for the sources tarball.
- Remove unnecessary project.diff file.

- Add CVE-2022-28346.patch (bsc#1198398, CVE-2022-28346)
* Potential SQL injection in QuerySet.annotate(),aggregate() and extra()
- Add CVE-2022-34265.patch (bsc#1201186, CVE-2022-34265)
* SQL injection via Trunc(kind) and Extract(lookup_name) arguments

- CVE-2021-45452.patch: added missing attribute to validate_file_name (bsc#1194116)

- Add CVE-2022-22818.patch (bsc#1195086, CVE-2022-22818)
* Possible XSS via ``{% debug %}`` template tag
- Add CVE-2022-23833.patch (bsc#1195088, CVE-2022-23833)
* Denial-of-service possibility in file uploads


Gayane Osipyan's avatar

gosipyan accepted request

Thanks!

openSUSE Build Service is sponsored by