A high-level Python Web framework that encourages rapid development and clean, pragmatic design.
Security Fix(es):
An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions cleanipv6address and isvalidipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)(CVE-2024-56374)
{ "severity": "Medium" }
{ "noarch": [ "python-django-help-4.2.15-4.oe2403.noarch.rpm", "python3-Django-4.2.15-4.oe2403.noarch.rpm", "python-django-help-4.2.15-4.oe2403sp1.noarch.rpm", "python3-Django-4.2.15-4.oe2403sp1.noarch.rpm" ], "src": [ "python-django-4.2.15-4.oe2403.src.rpm", "python-django-4.2.15-4.oe2403sp1.src.rpm" ] }