Overview

Request 1189777 accepted

- Add fix-cve-2023-23969.patch (CVE-2023-23969, bsc#1207565)
* CVE-2023-23969: Potential denial-of-service via
Accept-Language headers
- Add CVE-2024-38875.patch (CVE-2024-38875, bsc#1227590)
* CVE-2024-38875: Potential denial-of-service attack via
certain inputs with a very large number of brackets
- Add CVE-2024-39329.patch (CVE-2024-39329, bsc#1227593)
* CVE-2024-39329: Username enumeration through timing difference
for users with unusable passwords
- Add CVE-2024-39330.patch (CVE-2024-39330, bsc#1227594)
* CVE-2024-39330: Potential directory traversal in
django.core.files.storage.Storage.save()
- Add CVE-2024-39614.patch (CVE-2024-39614, bsc#1227595)
* CVE-2024-39614: Potential denial-of-service through
django.utils.translation.get_supported_language-variant()

Request History
Nico Krapp's avatar

nkrapp created request

- Add fix-cve-2023-23969.patch (CVE-2023-23969, bsc#1207565)
* CVE-2023-23969: Potential denial-of-service via
Accept-Language headers
- Add CVE-2024-38875.patch (CVE-2024-38875, bsc#1227590)
* CVE-2024-38875: Potential denial-of-service attack via
certain inputs with a very large number of brackets
- Add CVE-2024-39329.patch (CVE-2024-39329, bsc#1227593)
* CVE-2024-39329: Username enumeration through timing difference
for users with unusable passwords
- Add CVE-2024-39330.patch (CVE-2024-39330, bsc#1227594)
* CVE-2024-39330: Potential directory traversal in
django.core.files.storage.Storage.save()
- Add CVE-2024-39614.patch (CVE-2024-39614, bsc#1227595)
* CVE-2024-39614: Potential denial-of-service through
django.utils.translation.get_supported_language-variant()


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Maintenance Bot's avatar

maintbot added python-Django as a reviewer

Submission for python-Django by someone who is not maintainer in the devel project (devel:languages:python:django). Please review


Maintenance Bot's avatar

maintbot accepted review

ok


Markéta Machová's avatar

mcalabkova accepted review

good point, you should have the rights


Markéta Machová's avatar

mcalabkova approved review

good point, you should have the rights


Marcus Meissner's avatar

msmeissn moved maintenance target to openSUSE:Maintenance:18497


Marcus Meissner's avatar

msmeissn accepted request

accepted request 1189777:Thanks!

For information about the update, see https://build.opensuse.org/project/maintenance_incidents/openSUSE:Maintenance

openSUSE Build Service is sponsored by