ALT-PU-2020-3491-1
Package python3-module-django2.2 updated to version 2.2.17-alt1 for branch sisyphus in task 263255.
Closed vulnerabilities
BDU:2021-00719
Уязвимость реализации функции ForeignKeyRawIdWidget библиотеки Django, позволяющая нарушителю проводить межсайтовые сценарные атаки
BDU:2021-00780
Уязвимость библиотеки Django, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2021-00881
Уязвимость программной платформы для веб-приложений Django, связанная с связана с неправильными настройками прав доступа по умолчанию, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2021-00936
Уязвимость реализации режима FILE_UPLOAD_DIRECTORY_PERMISSIONS программной платформы для веб-приложений Django, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2024-11-21
CVE-2020-13254
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
- https://docs.djangoproject.com/en/3.0/releases/security/
- https://groups.google.com/d/msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
- [debian-lts-announce] 20200612 [SECURITY] [DLA 2233-2] python-django regression update
- FEDORA-2020-c2639662af
- https://security.netapp.com/advisory/ntap-20200611-0002/
- USN-4381-1
- USN-4381-2
- DSA-4705
- https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://docs.djangoproject.com/en/3.0/releases/security/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
- DSA-4705
- USN-4381-2
- USN-4381-1
- https://security.netapp.com/advisory/ntap-20200611-0002/
- FEDORA-2020-c2639662af
- [debian-lts-announce] 20200612 [SECURITY] [DLA 2233-2] python-django regression update
- https://groups.google.com/d/msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
Modified: 2024-11-21
CVE-2020-13596
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
- https://docs.djangoproject.com/en/3.0/releases/security/
- https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
- FEDORA-2020-c2639662af
- https://security.netapp.com/advisory/ntap-20200611-0002/
- USN-4381-1
- USN-4381-2
- DSA-4705
- https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://docs.djangoproject.com/en/3.0/releases/security/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.djangoproject.com/weblog/2020/jun/03/security-releases/
- DSA-4705
- USN-4381-2
- USN-4381-1
- https://security.netapp.com/advisory/ntap-20200611-0002/
- FEDORA-2020-c2639662af
- https://groups.google.com/forum/#%21msg/django-announce/pPEmb2ot4Fo/X-SMalYSBAAJ
Modified: 2024-11-21
CVE-2020-24583
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.
- https://docs.djangoproject.com/en/dev/releases/security/
- https://docs.djangoproject.com/en/dev/releases/security/
- https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDM
- https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDM
- https://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutU
- https://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutU
- FEDORA-2020-94407454d7
- FEDORA-2020-94407454d7
- FEDORA-2020-9c6b391162
- FEDORA-2020-9c6b391162
- FEDORA-2020-6941c0a65b
- FEDORA-2020-6941c0a65b
- https://security.netapp.com/advisory/ntap-20200918-0004/
- https://security.netapp.com/advisory/ntap-20200918-0004/
- USN-4479-1
- USN-4479-1
- https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
- https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
- https://www.openwall.com/lists/oss-security/2020/09/01/2
- https://www.openwall.com/lists/oss-security/2020/09/01/2
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
Modified: 2024-11-21
CVE-2020-24584
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
- https://docs.djangoproject.com/en/dev/releases/security/
- https://docs.djangoproject.com/en/dev/releases/security/
- https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDM
- https://groups.google.com/forum/#%21topic/django-announce/Gdqn58RqIDM
- https://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutU
- https://groups.google.com/forum/#%21topic/django-announce/zFCMdgUnutU
- FEDORA-2020-94407454d7
- FEDORA-2020-94407454d7
- FEDORA-2020-9c6b391162
- FEDORA-2020-9c6b391162
- FEDORA-2020-6941c0a65b
- FEDORA-2020-6941c0a65b
- https://security.netapp.com/advisory/ntap-20200918-0004/
- https://security.netapp.com/advisory/ntap-20200918-0004/
- USN-4479-1
- USN-4479-1
- https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
- https://www.djangoproject.com/weblog/2020/sep/01/security-releases/
- https://www.openwall.com/lists/oss-security/2020/09/01/2
- https://www.openwall.com/lists/oss-security/2020/09/01/2
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html