Fedora 40: python-django 2024-4a08381122 Security Advisory Updates
Summary
Django is a high-level Python Web framework that encourages rapid
development and a clean, pragmatic design. It focuses on automating as
much as possible and adhering to the DRY (Don't Repeat Yourself)
principle.
Update Information:
urlize and urlizetrunc were subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
Change Log
* Wed Sep 4 2024 Michel Lind
References
[ 1 ] Bug #2309746 - CVE-2024-45230: Potential denial-of-service vulnerability in django.utils.html.urlize()
https://bugzilla.redhat.com/show_bug.cgi?id=2309746
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4a08381122' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label