MGASA-2022-0104
Dashboard / Vulnerabilities / MGASA-2022-0104
MGASA-2022-0104
Summary: Updated python-django/python-asgiref packages fix security vulnerability
Details: The {% debug %} template tag didn't properly encode the current context posing an XSS attack vector (CVE-2022-22818). Passing certain inputs to multipart forms could result in an infinite loop when parsing files resulting in a denial of service (CVE-2022-23833). The python-django update necessitated a version update to python-asgiref as well.
References: https://advisories.mageia.org/MGASA-2022-0104.html, https://bugs.mageia.org/show_bug.cgi?id=29984, https://www.djangoproject.com/weblog/2022/feb/01/security-releases/
Affected packages
Package
Name: python-django
Purl: pkg:rpm/mageia/python-django?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
