ALT-BU-2022-5815-1
Branch sisyphus update bulletin.
Package python3-module-django updated to version 3.2.15-alt1 for branch sisyphus in task 305624.
Closed vulnerabilities
BDU:2022-04199
Уязвимость функции Trunc/Extract фреймворка для веб-разработки Django, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2022-34265
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://groups.google.com/forum/#%21forum/django-announce
- https://groups.google.com/forum/#%21forum/django-announce
- FEDORA-2023-8fed428c5e
- FEDORA-2023-8fed428c5e
- FEDORA-2023-a53ab7c969
- FEDORA-2023-a53ab7c969
- https://security.netapp.com/advisory/ntap-20220818-0006/
- https://security.netapp.com/advisory/ntap-20220818-0006/
- DSA-5254
- DSA-5254
- https://www.djangoproject.com/weblog/2022/jul/04/security-releases/
- https://www.djangoproject.com/weblog/2022/jul/04/security-releases/
Modified: 2024-11-21
CVE-2022-36359
An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a FileResponse when the filename is derived from user-supplied input.
- [oss-security] 20220803 Django: CVE-2022-36359: Potential reflected file download vulnerability in FileResponse.
- https://docs.djangoproject.com/en/4.0/releases/security/
- https://groups.google.com/g/django-announce/c/8cz--gvaJr4
- FEDORA-2023-8fed428c5e
- FEDORA-2023-a53ab7c969
- https://security.netapp.com/advisory/ntap-20220915-0008/
- DSA-5254
- https://www.djangoproject.com/weblog/2022/aug/03/security-releases/
- [oss-security] 20220803 Django: CVE-2022-36359: Potential reflected file download vulnerability in FileResponse.
- https://www.djangoproject.com/weblog/2022/aug/03/security-releases/
- DSA-5254
- https://security.netapp.com/advisory/ntap-20220915-0008/
- FEDORA-2023-a53ab7c969
- FEDORA-2023-8fed428c5e
- https://groups.google.com/g/django-announce/c/8cz--gvaJr4
- https://docs.djangoproject.com/en/4.0/releases/security/