MGASA-2022-0011
Dashboard / Vulnerabilities / MGASA-2022-0011
MGASA-2022-0011
Summary: Updated python-django packages fix security vulnerability
Details: UserAttributeSimilarityValidator incurred significant overhead evaluating submitted password that were artificially large in relative to the comparison values. On the assumption that access to user registration was unrestricted this provided a potential vector for a denial-of-service attack. (CVE-2021-45115) Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure or unintended method calls, if passed a suitably crafted key. (CVE-2021-45116) Storage.save() allowed directory-traversal if directly passed suitably crafted file names. (CVE-2021-45452)
References: https://advisories.mageia.org/MGASA-2022-0011.html, https://bugs.mageia.org/show_bug.cgi?id=29843, https://www.djangoproject.com/weblog/2022/jan/04/security-releases/, https://ubuntu.com/security/notices/USN-5204-1
Affected packages
Package
Name: python-django
Purl: pkg:rpm/mageia/python-django?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
