Описание
Security update for python-Django
This update for python-Django fixes the following issues:
- CVE-2024-27351: Fixed a regular expression DoS in django.utils.text.Truncator.words (bsc#1220358)
Список пакетов
openSUSE Leap 15.5
python3-Django-2.0.7-150000.1.17.1
Ссылки
- Link for SUSE-SU-2024:0902-1
- E-Mail link for SUSE-SU-2024:0902-1
- SUSE Security Ratings
- SUSE Bug 1220358
- SUSE CVE CVE-2024-27351 page
Описание
In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.
Затронутые продукты
openSUSE Leap 15.5:python3-Django-2.0.7-150000.1.17.1
Ссылки
- CVE-2024-27351
- SUSE Bug 1220358