python-django 2:2.2.12-1ubuntu0.6 source package in Ubuntu

Changelog

python-django (2:2.2.12-1ubuntu0.6) focal-security; urgency=medium

  * SECURITY UPDATE: Potential directory-traversal via uploaded files
    - debian/patches/CVE-2021-31542.patch: tighten path & file name
      sanitation in file uploads in django/core/files/storage.py,
      django/core/files/uploadedfile.py, django/core/files/utils.py,
      django/db/models/fields/files.py, django/http/multipartparser.py,
      django/utils/text.py, tests/file_storage/test_generate_filename.py,
      tests/file_uploads/tests.py, tests/utils_tests/test_text.py,
      tests/forms_tests/field_tests/test_filefield.py.
    - CVE-2021-31542

 -- Marc Deslauriers <email address hidden>  Wed, 28 Apr 2021 06:39:44 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Focal: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
python-django_2.2.12.orig.tar.gz 8.5 MiB 69897097095f336d5aeef45b4103dceae51c00afa6d3ae198a2a18e519791b7a
python-django_2.2.12-1ubuntu0.6.debian.tar.xz 39.9 KiB 7c4ece9b7fdfed473b9e95f1df8d5c6579738e3516a0416de6f8a71c214c16d6
python-django_2.2.12-1ubuntu0.6.dsc 2.8 KiB bff3d21299ef548f50b22e26723563b38df97f393f22aaea5ac77729eb4caded

View changes file

Binary packages built by this source

python-django-doc: High-level Python web development framework (documentation)

 Django is a high-level web application framework that loosely follows the
 model-view-controller design pattern.
 .
 Python's equivalent to Ruby on Rails, Django lets you build complex
 data-driven websites quickly and easily - Django focuses on automating as much
 as possible and adhering to the "Don't Repeat Yourself" (DRY) principle.
 .
 Django additionally emphasizes reusability and "pluggability" of components;
 many generic third-party "applications" are available to enhance projects or
 to simply to reduce development time even further.
 .
 This package contains the HTML documentation and example projects.

python3-django: High-level Python web development framework

 Django is a high-level web application framework that loosely follows the
 model-view-controller design pattern.
 .
 Python's equivalent to Ruby on Rails, Django lets you build complex
 data-driven websites quickly and easily - Django focuses on automating as much
 as possible and adhering to the "Don't Repeat Yourself" (DRY) principle.
 .
 Django additionally emphasizes reusability and "pluggability" of components;
 many generic third-party "applications" are available to enhance projects or
 to simply to reduce development time even further.
 .
 Notable features include:
  * An object-relational mapper (ORM)
  * Automatic admin interface
  * Elegant URL dispatcher
  * Form serialization and validation system
  * Templating system
  * Lightweight, standalone web server for development and testing
  * Internationalization support
  * Testing framework and client