Package Release Info

python3-Django-2.2.28-bp157.2.3.1

Update Info: openSUSE-2026-290
Available in Package Hub : 15 SP7 Update

platforms

AArch64
ppc64le
s390x
x86-64

subpackages

python3-Django

Change Logs

* Wed Aug 05 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-15307: server-side file-write and request forgery via
    spatial lookups (bsc#1272997)
  * CVE-2026-15307.patch
  * CVE-2026-15337: potential denial-of-service vulnerability in
    `check_for_language()` (bsc#1272998)
  * CVE-2026-15337.patch
  * CVE-2026-15830: potential denial-of-service vulnerability via
    nested geometry collections (bsc#1272999)
  * CVE-2026-15830.patch
  * CVE-2026-15920: potential cross-site scripting via `URLField`
    values in the admin (bsc#1273000)
  * CVE-2026-15920.patch
* Thu Jul 09 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-48588: Potential exposure of private data via cached
    Set-Cookie response (bsc#1271029)
  * CVE-2026-48588.patch
  * CVE-2026-53877: Heap buffer over-read in GDALRaster (bsc#1271030)
  * CVE-2026-53877.patch
* Tue Jun 09 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-6873: Signed cookie salt namespace collision (bsc#1267578)
  * CVE-2026-6873.patch
  * CVE-2026-7666: Potential unencrypted email transmission via STARTTLS
    in the SMTP backend (bsc#1267579)
  * CVE-2026-7666.patch
  * CVE-2026-8404: Potential exposure of private data via case-sensitive
    Cache-Control directives (bsc#1267580)
  * CVE-2026-8404.patch
  * CVE-2026-35193: Potential exposure of private data via missing
    Vary: Authorization (bsc#1267576)
  * CVE-2026-35193.patch
  * CVE-2026-48587: Potential exposure of private data via whitespace
    padding in Vary header (bsc#1267577)
  * CVE-2026-48587.patch
* Wed May 06 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-5766: Potential denial-of-service vulnerability in ASGI
    requests via file upload limit bypass (bsc#1264153)
  * CVE-2026-5766.patch
  * CVE-2026-35192: Session fixation via public cached pages and
    SESSION_SAVE_EVERY_REQUEST (bsc#1264154)
  * CVE-2026-35192.patch
  * CVE-2026-6907: Potential exposure of private data due to incorrect
    handling of Vary: * in UpdateCacheMiddleware (bsc#1264152)
  * CVE-2026-6907.patch
* Thu Apr 09 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin
    (bsc#1261731)
  * CVE-2026-4277.patch
  * CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable
    (bsc#1261732)
  * CVE-2026-4292.patch
  * CVE-2026-33033: Potential denial-of-service vulnerability in
    MultiPartParser via base64-encoded file upload (bsc#1261722)
  * CVE-2026-33033.patch
* Wed Mar 04 2026 Markéta Machová <mmachova@suse.com>
- CVE-2026-25674: python-Django: race condition can lead to potential
  incorrect permissions on newly created file system objects
  (bsc#1259142)
  * CVE-2026-25674.patch
* Thu Feb 26 2026 Markéta Machová <mmachova@suse.com>
- Let django-admin be the master alternative
  * django-admin.py was dropped in newer releases of Django
  * uninstall the alternatives in postun as is standard in SUSE
* Tue Feb 03 2026 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2026-1312.patch (bsc#1257408)
  * CVE-2026-1312-followup.patch (bsc#1257408)
  * CVE-2026-1287.patch (bsc#1257407)
  * CVE-2026-1207.patch (bsc#1257405)
  * CVE-2025-13473.patch (bsc#1257401)
  * CVE-2026-1285.patch (bsc#1257406)
* Tue Dec 09 2025 Markéta Machová <mmachova@suse.com>
- Add security patches (bsc#1254437):
  * CVE-2025-13372.patch
  * CVE-2025-64460.patch
* Thu Nov 06 2025 Markéta Machová <mmachova@suse.com>
- Add security patch CVE-2025-64459.patch (bsc#1252926)
* Thu Oct 02 2025 Markéta Machová <mmachova@suse.com>
- Add security patches:
  * CVE-2025-59681.patch (bsc#1250485)
  * CVE-2025-59682.patch (bsc#1250487)
* Thu Sep 04 2025 Markéta Machová <mmachova@suse.com>
- Add security patch CVE-2025-57833.patch (bsc#1248810)
- Add upstream test_strip_tags.patch to fix build with patched python
* Thu Jul 03 2025 Markéta Machová <mmachova@suse.com>
- Add CVE-2025-48432-followup.patch as an "additional hardening"
  regarding CVE-2025-48432 (bsc#1244095)
* Fri Jun 06 2025 Markéta Machová <mmachova@suse.com>
- Add security patch CVE-2025-48432.patch (bsc#1244095)
Version: 2.2.28-bp157.1.1
* Mon May 19 2025 Markéta Machová <mmachova@suse.com>
- Add some forgotten security patches:
  * CVE-2024-53907.patch (bsc#1234232)
  * CVE-2025-26699.patch (bsc#1239052)
  * CVE-2025-32873.patch (bsc#1242210)
- Add upstream patch urlvalidator.patch to fix tests
* Wed Jan 15 2025 Markéta Machová <mmachova@suse.com>
- Add security patch CVE-2024-56374.patch (bsc#1235856)
* Tue Sep 03 2024 Markéta Machová <mmachova@suse.com>
- Add more (mostly) security patches:
  * unescape.patch
  * needed for the tests to work
  * CVE-2024-45230.patch (bsc#1229823)
  * CVE-2024-45231.patch (bsc#1229824)
* Thu Aug 08 2024 Markéta Machová <mmachova@suse.com>
- Add bunch of (mostly) security patches:
  * Decimal.patch
  * needed for CVE-2024-41989.patch to pass tests
  * CVE-2024-42005.patch (bsc#1228629)
  * CVE-2024-41989.patch (bsc#1228630)
  * CVE-2024-41990.patch (bsc#1228631)
  * CVE-2024-41991.patch (bsc#1228632)
* Mon Jul 22 2024 Nico Krapp <nico.krapp@suse.com>
- Add fix-cve-2023-23969.patch (CVE-2023-23969, bsc#1207565)
  * CVE-2023-23969: Potential denial-of-service via
    Accept-Language headers
- Add CVE-2024-38875.patch (CVE-2024-38875, bsc#1227590)
  * CVE-2024-38875: Potential denial-of-service attack via
    certain inputs with a very large number of brackets
- Add CVE-2024-39329.patch (CVE-2024-39329, bsc#1227593)
  * CVE-2024-39329: Username enumeration through timing difference
    for users with unusable passwords
- Add CVE-2024-39330.patch (CVE-2024-39330, bsc#1227594)
  * CVE-2024-39330: Potential directory traversal in
    django.core.files.storage.Storage.save()
- Add CVE-2024-39614.patch (CVE-2024-39614, bsc#1227595)
  * CVE-2024-39614: Potential denial-of-service through
    django.utils.translation.get_supported_language-variant()
* Thu Feb 29 2024 Alberto Planas Dominguez <aplanas@suse.com>
- Add fix_test_lazy_addresses.patch to fix test
- Add CVE-2024-27351.patch patch (CVE-2024-27351, bsc#1220358)
* Mon Oct 16 2023 Daniel Garcia Moreno <daniel.garcia@suse.com>
- Add CVE-2023-43665.patch (bsc#1215978, CVE-2023-43665)
  * Denial-of-service possibility in django.utils.text.Truncator
* Mon Jul 10 2023 Alberto Planas Dominguez <aplanas@suse.com>
- Add fix-cve-2023-36053.patch (bsc#1212742, CVE-2023-36053)
* Thu Feb 23 2023 Matej Cepl <mcepl@suse.com>
- Add CVE-2023-24580-DOS_file_upload.patch (CVE-2023-24580,
  bsc#1208082) to prevent DOS in file uploads.
* Thu Feb 02 2023 Alberto Planas Dominguez <aplanas@suse.com>
- Add fix-cve-2023-23969.patch (bsc#1207565, CVE-2023-23969)
* Tue Oct 04 2022 Alberto Planas Dominguez <aplanas@suse.com>
- Add fix-cve-2022-41323.patch (bsc#1203793, CVE-2022-41323)
  * Backport fix and tests from uptream branch 3.2.X
- Add test_custom_fields.patch
  * Required to fix an inspectdb test
* Mon Aug 08 2022 Alberto Planas Dominguez <aplanas@suse.com>
- Add fix-cve-2022-36359.patch (CVE-2022-36359, bsc#1201923)
  * Backport fix and tests from uptream branch 3.2.X
- Rename Django-2.2.28.tar.gz.asc to Django-2.2.28.checksum.txt
  * The source validator try to validate the signature agains
    Django-2.2.28.tar.gz, instead of the checksum message itself
* Mon Apr 11 2022 Alberto Planas Dominguez <aplanas@suse.com>
- Update to 2.2.28 (bsc#1198297)
  * Many CVEs fixes (check https://github.com/django/django/blob/main/docs/releases/)
* Fri Apr 03 2020 Tomáš Chvátal <tchvatal@suse.com>
- Update to 2.2.12:
  * Added the ability to handle .po files containing different plural
    equations for the same language (#30439).
* Wed Mar 18 2020 Ondřej Súkup <mimi.vx@gmail.com>
- update to 2.2.11
  * fix boo#1165022 (CVE-2020-9402) Potential SQL injection via tolerance
  parameter in GIS functions and aggregates on Oracle
* Tue Feb 04 2020 Ondřej Súkup <mimi.vx@gmail.com>
- update to 2.2.10
- drop pyyaml53.patch
  * fix boo#1161919 (CVE-2020-7471) Potential SQL injection via ``StringAgg(delimiter)``
* Wed Jan 15 2020 Ondřej Súkup <mimi.vx@gmail.com>
- add pyyaml53.patch - fix tests with PyYAML 5.3
* Sun Dec 29 2019 Ondřej Súkup <mimi.vx@gmail.com>
- Update to 2.2.9
  * CVE-2019-19844: Potential account hijack via password reset form (bsc#1159447)
  * Fixed a data loss possibility in SplitArrayField.
* Mon Dec 02 2019 Alberto Planas Dominguez <aplanas@suse.com>
- Update to 2.2.8
  * CVE-2019-19118: Privilege escalation in the Django admin (boo#1157705)
  * Fixed a data loss possibility in the admin changelist view when a
    custom formset’s prefix contains regular expression special
    characters, e.g. '$'
  * Fixed a regression in Django 2.2.1 that caused a crash when
    migrating permissions for proxy models with a multiple database
    setup if the default entry was empty
  * Fixed a data loss possibility in the select_for_update(). When
    using 'self' in the of argument with multi-table inheritance, a
    parent model was locked instead of the queryset’s model
- Add patch fix-selenium-test.patch to fix a test when selenium is
  missing
* Fri Nov 15 2019 Tomáš Chvátal <tchvatal@suse.com>
- Update to 2.2.7:
  * Fixed a crash when using a contains, contained_by, has_key, has_keys, or has_any_keys lookup on JSONField, if the right or left hand side of an expression is a key transform (#30826).
  * Prevented migrate --plan from showing that RunPython operations are irreversible when reverse_code callables don’t have docstrings or when showing a forward migration plan (#30870).
  * Fixed migrations crash on PostgreSQL when adding an Index with fields ordering and opclasses (#30903).
  * Restored the ability to override get_FOO_display() (#30931).