[Git][security-tracker-team/security-tracker][master] python-django in jessie LTS is not vulnerable to CVE-2019-14234
Chris Lamb
lamby at debian.org
Tue Aug 6 10:26:04 BST 2019
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2dc2c871 by Chris Lamb at 2019-08-06T09:25:18Z
python-django in jessie LTS is not vulnerable to CVE-2019-14234
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1749,6 +1749,7 @@ CVE-2019-14235 (An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x b
CVE-2019-14234 [SQL injection possibility in key and index lookups for JSONField/HStoreField]
RESERVED
- python-django <unfixed> (bug #934026)
+ [jessie] - python-django <not-affected> (Vulnerable code not present)
NOTE: https://www.djangoproject.com/weblog/2019/aug/01/security-releases/
NOTE: https://github.com/django/django/commit/4f5b58f5cd3c57fee9972ab074f8dc6895d8f387 (2.2.x)
NOTE: https://github.com/django/django/commit/ed682a24fca774818542757651bfba576c3fc3ef (1.11.x)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2dc2c87112b7f9adbb1abf2ba15089e78ab49580
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/2dc2c87112b7f9adbb1abf2ba15089e78ab49580
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190806/c0d3ec9f/attachment.html>
More information about the debian-security-tracker-commits
mailing list