10 Commits

Author SHA256 Message Date
2f8a63dcf8 Accepting request 1198655 from devel:languages:python:django
OBS-URL: https://build.opensuse.org/request/show/1198655
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/python-Django4?expand=0&rev=4
2024-09-04 11:27:30 +00:00
1b0ae71e2e - Update to 4.2.16 (bsc#1229823, bsc#1229824)
* CVE-2024-45230: Potential denial-of-service vulnerability in 
    django.utils.html.urlize()
  * CVE-2024-45231: Potential user email enumeration via response 
    status on password reset

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=9
2024-09-04 07:53:45 +00:00
a4b4168d0d Accepting request 1192592 from devel:languages:python:django
- Update to 4.2.15 (bsc#1228629, bsc#1228630, bsc#1228631, bsc#1228632)

OBS-URL: https://build.opensuse.org/request/show/1192592
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/python-Django4?expand=0&rev=3
2024-08-09 14:15:06 +00:00
a8117dacb3 add bugzilla entries for the CVEs
OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=7
2024-08-08 10:36:36 +00:00
5de29dc3a3 Accepting request 1192059 from devel:languages:python:django
OBS-URL: https://build.opensuse.org/request/show/1192059
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/python-Django4?expand=0&rev=2
2024-08-08 08:57:34 +00:00
7d8d017df2 - Update to 4.2.15
* CVE-2024-41989: Memory exhaustion in
    django.utils.numberformat.floatformat()
  * CVE-2024-41990: Potential denial-of-service vulnerability in
    django.utils.html.urlize()
  * CVE-2024-41991: Potential denial-of-service vulnerability in
    django.utils.html.urlize() and AdminURLFieldWidget
  * CVE-2024-42005: Potential SQL injection in QuerySet.values() and
    values_list()
  * Fixed a regression in Django 4.2.14 that caused a crash in
    LocaleMiddleware when processing a language code over 500
    characters

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=5
2024-08-07 06:25:00 +00:00
4ad33dfe4e Accepting request 1188323 from devel:languages:python:django
backport of older Django

OBS-URL: https://build.opensuse.org/request/show/1188323
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/python-Django4?expand=0&rev=1
2024-07-19 13:28:57 +00:00
95863643bc add conflicts
OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=3
2024-07-18 06:52:36 +00:00
b3901740cf - Update to 4.2.14
* Django 4.2.14 fixes two security issues with severity “moderate” 
    and two security issues with severity “low" in 4.2.13
  * CVE-2024-38875: Potential denial-of-service vulnerability in 
    django.utils.html.urlize() (bsc#1227590)
  * CVE-2024-39329: Username enumeration through timing difference 
    for users with unusable passwords (bsc#1227593)
  * CVE-2024-39330: Potential directory-traversal via Storage.save()
    (bsc#1227594)
  * CVE-2024-39614: Potential denial-of-service vulnerability in 
    get_supported_language_variant() (bsc#1227595)

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=2
2024-07-17 14:44:09 +00:00
9ff65d6710 Django 4.x for HyperKitty
OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:django/python-Django4?expand=0&rev=1
2024-07-17 14:26:39 +00:00