Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:03446-1

Опубликовано: 02 окт. 2025
Источник: suse-cvrf

Описание

Security update for python-Django

This update for python-Django fixes the following issues:

  • CVE-2025-59681: SQL injection via the QuerySet annotate(), alias(), aggregate(), or extra()` methods when processing a specially crafted dictionary with dictionary expansion (bsc#1250485).
  • CVE-2025-59682: directory traversal via the django.utils.archive.extract() function when processing an archive with file paths that share a common prefix with the target directory (bsc#1250487).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP6
python311-Django-4.2.11-150600.3.33.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
python311-Django-4.2.11-150600.3.33.1
openSUSE Leap 15.6
python311-Django-4.2.11-150600.3.33.1

Описание

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:python311-Django-4.2.11-150600.3.33.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python311-Django-4.2.11-150600.3.33.1
openSUSE Leap 15.6:python311-Django-4.2.11-150600.3.33.1

Ссылки

Описание

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:python311-Django-4.2.11-150600.3.33.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python311-Django-4.2.11-150600.3.33.1
openSUSE Leap 15.6:python311-Django-4.2.11-150600.3.33.1

Ссылки