UbuntuUpdates.org

Package "python-django"

Name: python-django

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • High-level Python web development framework (documentation)
  • High-level Python web development framework

Latest version: 2:3.2.12-2ubuntu1.22
Release: jammy (22.04)
Level: updates
Repository: main

Links



Other versions of "python-django" in Jammy

Repository Area Version
base main 2:3.2.12-2ubuntu1
security main 2:3.2.12-2ubuntu1.22

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:3.2.12-2ubuntu1.22 2025-10-02 11:07:04 UTC

  python-django (2:3.2.12-2ubuntu1.22) jammy-security; urgency=medium

  * SECURITY UPDATE: Potential SQL injection
    - debian/patches/CVE-2025-59681.patch: protect against SQL injection in
      django/db/models/sql/query.py, tests/aggregation/tests.py,
      tests/annotations/tests.py,
      tests/expressions/test_queryset_values.py, tests/queries/tests.py.
    - CVE-2025-59681
  * SECURITY UPDATE: Potential partial directory-traversal
    - debian/patches/CVE-2025-59682.patch: validate path in
      django/utils/archive.py, tests/utils_tests/test_archive.py.
    - CVE-2025-59682

 -- Marc Deslauriers <email address hidden> Wed, 24 Sep 2025 12:28:31 -0400

Source diff to previous version
CVE-2025-59681 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggrega
CVE-2025-59682 An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by th

Version: 2:3.2.12-2ubuntu1.21 2025-09-04 00:07:52 UTC

  python-django (2:3.2.12-2ubuntu1.21) jammy-security; urgency=medium

  * SECURITY UPDATE: SQL injection
    - debian/patches/CVE-2025-57833.patch: protected
      FilteredRelation against SQL injection in column
      aliases in django/db/models/sql/query.py,
      tests/annotations/tests.py.
    - debian/patches/skipping_tests.patch: skipping
      FTBFS tests test_strip_tags.
    - CVE-2025-57833

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 01 Sep 2025 13:01:20 -0300

Source diff to previous version

Version: 2:3.2.12-2ubuntu1.20 2025-06-16 18:07:30 UTC

  python-django (2:3.2.12-2ubuntu1.20) jammy-security; urgency=medium

  * SECURITY UPDATE: Prevented log injection
    - debian/patches/CVE-2025-48432-2.patch: prevented log injection in
      remaining response logging in django/views/generic/base.py,
      test/generic_views/test_base.py (LP: #2113924)

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 11 Jun 2025 16:31:28 -0300

Source diff to previous version
2113924 Incomplete fix for CVE-2025-48432
CVE-2025-48432 Potential log injection via unescaped request path

Version: 2:3.2.12-2ubuntu1.19 2025-06-05 22:07:28 UTC

  python-django (2:3.2.12-2ubuntu1.19) jammy-security; urgency=medium

  * SECURITY UPDATE: Log structure manipulation
    - debian/patches/CVE-2025-48432.patch: escape formatting
      arguments in log_response() in django/utils/log.py,
      tests/logging_tests/tests.py.
    - CVE-2025-48432

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 02 Jun 2025 08:11:47 -0300

Source diff to previous version
CVE-2025-48432 Potential log injection via unescaped request path

Version: 2:3.2.12-2ubuntu1.18 2025-05-07 20:07:18 UTC

  python-django (2:3.2.12-2ubuntu1.18) jammy-security; urgency=medium

  * SECURITY UPDATE: Denial of service in strip_tags()
    - debian/patches/CVE-2025-32873.patch: check tag depth in
      django/utils/html.py, tests/utils_tests/test_html.py.
    - CVE-2025-32873

 -- Marc Deslauriers <email address hidden> Wed, 30 Apr 2025 10:34:27 -0400




About   -   Send Feedback to @ubuntu_updates