Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/674F199BF2173F0795EA8E8DB982958C
HistoryJul 13, 2021 - 12:00 a.m.

Security fix for the ALT Linux 10 package python3-module-django version 2.2.24-alt1

2021-07-1300:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
9

0.008 Low

EPSS

Percentile

81.2%

July 13, 2021 Alexey Shabalin 2.2.24-alt1

- new version 2.2.24
- Fixes for the following security vulnerabilities:
  + CVE-2021-28658 Potential directory-traversal via uploaded files
  + CVE-2021-31542 Potential directory-traversal via uploaded files
  + CVE-2021-32052 Header injection possibility since URLValidator accepted newlines in input on Python 3.9.5+
  + CVE-2021-33203 Potential directory traversal via admindocs
  + CVE-2021-33571 Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses