Security update for python-Django
This update for python-Django fixes the following issues: - CVE-2023-23969: Potential denial-of-service via Accept-Language headers (boo#1207565) - CVE-2024-38875: Potential denial-of-service attack via certain inputs with a very large number of brackets (boo#1227590) - CVE-2024-39329: Username enumeration through timing difference for users with unusable passwords (boo#1227593) - CVE-2024-39330: Potential directory traversal in django.core.files.storage.Storage.save() (boo#1227594) - CVE-2024-39614: Potential denial-of-service through django.utils.translation.get_supported_language-variant() (boo#1227595)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Django fixes the following issues: - CVE-2023-23969: Potential denial-of-service via Accept-Language headers (boo#1207565) - CVE-2024-38875: Potential denial-of-service attack via certain inputs with a very large number of brackets (boo#1227590) - CVE-2024-39329: Username enumeration through timing difference for users with unusable passwords (boo#1227593) - CVE-2024-39330: Potential directory traversal in django.core.files.storage.Storage.save() (boo#1227594) - CVE-2024-39614: Potential denial-of-service through django.utils.translation.get_supported_language-variant() (boo#1227595)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1207565
- https://bugzilla.suse.com/1227590
- https://bugzilla.suse.com/1227593
- https://bugzilla.suse.com/1227594
- https://bugzilla.suse.com/1227595
- https://lists.opensuse.org/archives/list/[email protected]/thread/OU4KXNSFOQVRSGL2OQCMRA3EFMPZEGEU/
- https://www.suse.com/security/cve/CVE-2023-23969
- https://www.suse.com/security/cve/CVE-2024-38875
- https://www.suse.com/security/cve/CVE-2024-39329
- https://www.suse.com/security/cve/CVE-2024-39330
- https://www.suse.com/security/cve/CVE-2024-39614