First published: Wed Oct 28 2020(Updated: )
Django is a high-level Python Web framework that encourages rapid<br>development and a clean, pragmatic design. It focuses on automating as much<br>as possible and adhering to the DRY (Don't Repeat Yourself) principle.<br>Security Fix(es):<br><li> Incorrect HTTP detection with reverse-proxy connecting via HTTPS</li> (CVE-2019-12781)<br><li> backtracking in a regular expression in django.utils.text.Truncator leads</li> to DoS (CVE-2019-14232)<br><li> the behavior of the underlying HTMLParser leading to DoS (CVE-2019-14233)</li> <li> SQL injection possibility in key and index lookups for</li> JSONField/HStoreField (CVE-2019-14234)<br><li> Potential memory exhaustion in django.utils.encoding.uri_to_iri()</li> (CVE-2019-14235)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-django | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/python-django-bash-completion | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/python2-django | <1.11.27-1.el7 | 1.11.27-1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.