openSUSE-SU-2023:0178-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0178-1
openSUSE-SU-2023:0178-1
Summary: Security update for python-Django
Details: This update for python-Django fixes the following issues: - CVE-2023-36053: Fixed potential regular expression denial of service vulnerability in EmailValidator/URLValidator (boo#1212742) - CVE-2023-24580: Fixed potential denial-of-service vulnerability in file uploads (boo#1208082) - CVE-2023-23969: Fixed potential denial-of-service via Accept-Language headers (boo#1207565) - CVE-2022-41323: Fixed potential denial-of-service vulnerability in internationalized URLs (boo#1203793)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/XIBAQZUQ2RHKRUEWEHTVUYM66J3IOWLL/, https://bugzilla.suse.com/1203793, https://bugzilla.suse.com/1207565, https://bugzilla.suse.com/1208082, https://bugzilla.suse.com/1212742, https://www.suse.com/security/cve/CVE-2022-41323, https://www.suse.com/security/cve/CVE-2023-23969, https://www.suse.com/security/cve/CVE-2023-24580, https://www.suse.com/security/cve/CVE-2023-36053
Affected packages
Package
Name: python-Django
Purl: pkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
