UbuntuUpdates.org

Package "python3-django"

Name: python3-django

Description:

High-level Python web development framework

Latest version: 2:3.2.12-2ubuntu1.22
Release: jammy (22.04)
Level: security
Repository: main
Head package: python-django
Homepage: http://www.djangoproject.com/

Links


Download "python3-django"


Other versions of "python3-django" in Jammy

Repository Area Version
base main 2:3.2.12-2ubuntu1
updates main 2:3.2.12-2ubuntu1.22

Changelog

Version: 2:3.2.12-2ubuntu1.22 2025-10-02 07:07:30 UTC

  python-django (2:3.2.12-2ubuntu1.22) jammy-security; urgency=medium

  * SECURITY UPDATE: Potential SQL injection
    - debian/patches/CVE-2025-59681.patch: protect against SQL injection in
      django/db/models/sql/query.py, tests/aggregation/tests.py,
      tests/annotations/tests.py,
      tests/expressions/test_queryset_values.py, tests/queries/tests.py.
    - CVE-2025-59681
  * SECURITY UPDATE: Potential partial directory-traversal
    - debian/patches/CVE-2025-59682.patch: validate path in
      django/utils/archive.py, tests/utils_tests/test_archive.py.
    - CVE-2025-59682

 -- Marc Deslauriers <email address hidden> Wed, 24 Sep 2025 12:28:31 -0400

Source diff to previous version
CVE-2025-59681 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega
CVE-2025-59682 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by th

Version: 2:3.2.12-2ubuntu1.21 2025-09-03 22:07:36 UTC

  python-django (2:3.2.12-2ubuntu1.21) jammy-security; urgency=medium

  * SECURITY UPDATE: SQL injection
    - debian/patches/CVE-2025-57833.patch: protected
      FilteredRelation against SQL injection in column
      aliases in django/db/models/sql/query.py,
      tests/annotations/tests.py.
    - debian/patches/skipping_tests.patch: skipping
      FTBFS tests test_strip_tags.
    - CVE-2025-57833

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 01 Sep 2025 13:01:20 -0300

Source diff to previous version

Version: 2:3.2.12-2ubuntu1.20 2025-06-16 14:07:03 UTC

  python-django (2:3.2.12-2ubuntu1.20) jammy-security; urgency=medium

  * SECURITY UPDATE: Prevented log injection
    - debian/patches/CVE-2025-48432-2.patch: prevented log injection in
      remaining response logging in django/views/generic/base.py,
      test/generic_views/test_base.py (LP: #2113924)

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 11 Jun 2025 16:31:28 -0300

Source diff to previous version
2113924 Incomplete fix for CVE-2025-48432
CVE-2025-48432 Potential log injection via unescaped request path

Version: 2:3.2.12-2ubuntu1.19 2025-06-04 22:07:46 UTC

  python-django (2:3.2.12-2ubuntu1.19) jammy-security; urgency=medium

  * SECURITY UPDATE: Log structure manipulation
    - debian/patches/CVE-2025-48432.patch: escape formatting
      arguments in log_response() in django/utils/log.py,
      tests/logging_tests/tests.py.
    - CVE-2025-48432

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 02 Jun 2025 08:11:47 -0300

Source diff to previous version
CVE-2025-48432 Potential log injection via unescaped request path

Version: 2:3.2.12-2ubuntu1.18 2025-05-07 19:07:26 UTC

  python-django (2:3.2.12-2ubuntu1.18) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service in strip_tags()
    - debian/patches/CVE-2025-32873.patch: check tag depth in
      django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2025-32873

 -- Marc Deslauriers <email address hidden> Wed, 30 Apr 2025 10:34:27 -0400




About   -   Send Feedback to @ubuntu_updates