openSUSE-SU-2024:0017-1
Dashboard / Vulnerabilities / openSUSE-SU-2024:0017-1
openSUSE-SU-2024:0017-1
Summary: Security update for python-django-grappelli
Details: This update for python-django-grappelli fixes the following issues: Update to 2.14.4: - CVE-2021-46898: Fixed views/switch.py vulnerable to protocol-relative URL attacks (boo#1216481) - Fixed: Redirect with switch user. - Improved: Remove extra filtering in AutocompleteLookup. - Improved: Added import statement with URLs for quickstart docs. - Improved: Added additional blocks with inlines to allow override. - Fixed: Compatibility with Django 3.1. - Fixed: Docs about adding Grappelli documentation URLS.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/3GF4HWC4HAGFXA56AYL7TL7B3KA2SM45/, https://bugzilla.suse.com/1216481, https://www.suse.com/security/cve/CVE-2021-46898
Affected packages
Package
Name: python-django-grappelli
Purl: pkg:rpm/suse/python-django-grappelli&distro=SUSE%20Package%20Hub%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
