RHSA-2022:8872: Important: Red Hat OpenStack Platform 16.1.9 (python-django20) security update
Security Fix(es): SQL injection in QuerySet.annotate() aggregate() and extra() (CVE-2022-28346) Possible XSS via '{% debug %}' template tag (CVE-2022-22818) Denial of service possibility in file uploads (CVE-2022-23833) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:8872?
The severity of RHSA-2022:8872 is high due to multiple vulnerabilities including SQL injection and XSS.
How do I fix RHSA-2022:8872?
To fix RHSA-2022:8872, upgrade to the patched version 2.0.13-18.el8 of the affected Django packages.
What types of vulnerabilities are addressed in RHSA-2022:8872?
RHSA-2022:8872 addresses SQL injection, possible XSS, and denial of service vulnerabilities.
Which software packages are affected by RHSA-2022:8872?
RHSA-2022:8872 affects the python-django20, python-django20-bash-completion, and python3-django20 packages.
What are the specific CVEs associated with RHSA-2022:8872?
The specific CVEs associated with RHSA-2022:8872 are CVE-2022-28346, CVE-2022-22818, and CVE-2022-23833.