[ubuntu-cloud-archive/ussuri-proposed] python-django (Accepted)

Corey Bryant corey.bryant at canonical.com
Mon Mar 1 20:12:40 UTC 2021


 python-django (2:2.2.12-1ubuntu0.4~cloud0) bionic-ussuri; urgency=medium
 .
   * New update for the Ubuntu Cloud Archive.
 .
 python-django (2:2.2.12-1ubuntu0.4) focal-security; urgency=medium
 .
   * SECURITY UPDATE: Web cache poisoning via limited_parse_qsl()
     - debian/patches/CVE-2021-23336.patch: no longer allow ; in parse_qsl()
       in django/utils/http.py, tests/handlers/test_exception.py,
       tests/requests/test_data_upload_settings.py,
       tests/utils_tests/test_http.py.
     - CVE-2021-23336

Date: Mon, 22 Feb 2021 14:41:22 +0000
Changed-By: Openstack Ubuntu Testing Bot <openstack-testing-bot at ubuntu.com>
Signed-By: Openstack Ubuntu Testing Bot
Published-By: Corey Bryant <corey.bryant at canonical.com>


More information about the Cloud-archive-changes mailing list