Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2816


Security update for python-Django


Type: security
Severity: important
Issued: 2024-08-07
Description:
This update for python-Django fixes the following issues:

- CVE-2024-42005: Fixed SQL injection in QuerySet.values() and values_list() (bsc#1228629)
- CVE-2024-41989: Fixed Memory exhaustion in django.utils.numberformat.floatformat() (bsc#1228630)
- CVE-2024-41990: Fixed denial-of-service vulnerability in django.utils.html.urlize() (bsc#1228631)
- CVE-2024-41991: Fixed another denial-of-service vulnerability in django.utils.html.urlize() (bsc#1228632)


              

Packages


  • python-Django-4.2.11-150600.3.6.1