Files
buildroot/package
Titouan Christophe cbb64ac48d package/python-django: security bump to v5.1.13
This fixes the following vulnerabilities:
- CVE-2025-59681:
    An issue was discovered in Django 4.2 before 4.2.25, 5.1 before
    5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(),
    QuerySet.aggregate(), and QuerySet.extra() are subject to SQL
    injection in column aliases, when using a suitably crafted dictionary,
    with dictionary expansion, as the **kwargs passed to these methods (on
    MySQL and MariaDB).
    https://www.cve.org/CVERecord?id=CVE-2025-59681

- CVE-2025-59682:
    An issue was discovered in Django 4.2 before 4.2.25, 5.1 before
    5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract()
    function, used by the "startapp --template" and "startproject
    --template" commands, allows partial directory traversal via an
    archive with file paths sharing a common prefix with the target
    directory.
    https://www.cve.org/CVERecord?id=CVE-2025-59682

Signed-off-by: Titouan Christophe <titouan.christophe@mind.be>
(cherry picked from commit 7bbc66a39e)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2025-10-09 08:42:49 +02:00
..
…
…
…
2025-08-14 09:25:51 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2025-09-25 22:07:18 +02:00
…
…
…
…
…
2025-08-07 11:06:45 +02:00
…
…
…
…
…
…
…
…
2025-07-10 11:20:09 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
2025-09-05 17:08:13 +02:00
…
…
…
…
…
…
…
…
…
…
…
2025-08-14 09:25:59 +02:00
…
…
…
…
…
…
…
…
…
…
2025-07-10 11:23:04 +02:00
…
…
…
…
…
…
2025-07-11 14:21:45 +02:00
…
…
…
…
2025-09-04 13:57:24 +02:00
…
…
…
…
…
…
…
2025-07-10 11:21:28 +02:00
…
…
…
…
…
…
…
…
2025-09-08 12:36:55 +02:00
…
…
…
2025-08-14 09:26:47 +02:00
…
…
2025-09-11 17:14:42 +02:00
…
…
…
…
…
…
…
…
…
…
…
2025-08-21 10:41:39 +02:00
…
…
…
…
2025-08-07 11:06:39 +02:00
…
…
…
2025-09-18 16:44:46 +02:00
…
…
…
…
…
…
…
…
…
2025-05-26 17:49:10 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2025-07-03 09:11:14 +02:00
…
…
…
…
2025-07-03 09:49:08 +02:00
…
…
…
…
…
…
…
…
…
…
2025-06-12 14:40:44 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
2025-08-07 12:15:52 +02:00
…
…
2025-09-25 22:07:21 +02:00
…
…
…
2025-08-07 12:19:13 +02:00
…
…
…
…
…
…
…
…
…
…
2025-09-04 13:57:24 +02:00
…
…
…
…
…
…
…
…
2025-08-07 12:16:19 +02:00
…
…
2025-09-19 14:53:56 +02:00
…
2025-09-05 17:16:56 +02:00
…
…
…
…
…
2025-07-10 11:22:59 +02:00
2025-09-04 13:57:24 +02:00
…
…
…
…
…
…
…
…
…
…
…
2025-08-14 09:26:33 +02:00
…
…
…
2025-10-09 08:32:00 +02:00
…
…
…
…
2025-09-25 22:07:46 +02:00
…
…
…
…
2025-09-25 22:07:24 +02:00
…
…
…
…
2025-09-04 13:57:24 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2025-09-11 17:41:15 +02:00