[Git][security-tracker-team/security-tracker][master] Triage CVE-2019-19844 in python-django for jessie LTS.
Chris Lamb
lamby at debian.org
Thu Feb 6 15:40:56 GMT 2020
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
135ae0a8 by Chris Lamb at 2020-02-06T15:40:47+00:00
Triage CVE-2019-19844 in python-django for jessie LTS.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -12062,6 +12062,7 @@ CVE-2019-19845 (In Joomla! before 3.9.14, a missing access check in framework fi
CVE-2019-19844 (Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows a ...)
{DSA-4598-1 DLA-2042-1}
- python-django 2:2.2.9-1 (bug #946937)
+ [jessie] - python-django <not-affected> (Vulnerable code introduced in Django ~1.9)
NOTE: https://www.djangoproject.com/weblog/2019/dec/18/security-releases/
NOTE: https://github.com/django/django/commit/5b1fbcef7a8bec991ebe7b2a18b5d5a95d72cb70 (master)
NOTE: https://github.com/django/django/commit/302a4ff1e8b1c798aab97673909c7a3dfda42c26 (3.0.x branch)
=====================================
data/dla-needed.txt
=====================================
@@ -71,8 +71,6 @@ openjdk-7 (Emilio)
--
php5 (Thorsten Alteholz)
--
-python-django (Chris Lamb)
---
python-pysaml2 (Abhijith PA)
NOTE: 2020203: test fails already for the one in archive (abhijith)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/135ae0a8035afb2b107bd9f24ad3f6f659a7dab4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/135ae0a8035afb2b107bd9f24ad3f6f659a7dab4
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200206/356a53e3/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list