RHSA-2020:1324: Moderate: python-django security update
Django is a high-level Python Web framework that encourages rapiddevelopment and a clean, pragmatic design. It focuses on automating as muchas possible and adhering to the DRY (Don't Repeat Yourself) principle.Security Fix(es): Incorrect HTTP detection with reverse-proxy connecting via HTTPS (CVE-2019-12781) backtracking in a regular expression in django.utils.text.Truncator leads to DoS (CVE-2019-14232) the behavior of the underlying HTMLParser leading to DoS (CVE-2019-14233) SQL injection possibility in key and index lookups for JSONField/HStoreField (CVE-2019-14234) Potential memory exhaustion in django.utils.encoding.uritoiri() (CVE-2019-14235)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-djangoto a version that resolves this vulnerability.Fixed in 2.1.11-1.el8 - Upgrade
Upgrade
redhat/python-django-bash-completionto a version that resolves this vulnerability.Fixed in 2.1.11-1.el8 - Upgrade
Upgrade
redhat/python3-djangoto a version that resolves this vulnerability.Fixed in 2.1.11-1.el8
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1324?
The severity of RHSA-2020:1324 is noted as important, indicating significant security issues that need urgent attention.
How do I fix RHSA-2020:1324?
To fix RHSA-2020:1324, upgrade the affected packages to version 2.1.11-1.el8 or later.
Which software packages are affected by RHSA-2020:1324?
RHSA-2020:1324 affects python-django, python-django-bash-completion, and python3-django on Red Hat systems.
Is RHSA-2020:1324 a remote vulnerability?
Yes, RHSA-2020:1324 involves incorrect HTTP detection, which can be exploited remotely under certain conditions.
What are the potential impacts of not addressing RHSA-2020:1324?
Failing to address RHSA-2020:1324 may lead to unauthorized access or manipulation of web applications developed with Django.