QID 198320

Date Published: 2021-04-08

QID 198320: Ubuntu Security Notification for Python-django Vulnerability (USN-4902-1)

It was discovered that Django incorrectly handled certain filenames.

A remote attacker could possibly use this issue to create or overwrite files in unexpected directories.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Refer to Ubuntu advisory USN-4902-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198320

    Software Advisories
    Advisory ID Software Component Link
    USN-4902-1 16.04 (Xenial) on src python-django URL Logo launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.15
    USN-4902-1 16.04 (Xenial) on src python3-django URL Logo launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.15
    USN-4902-1 18.04 (bionic) on src python-django URL Logo launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.12
    USN-4902-1 18.04 (bionic) on src python3-django URL Logo launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.12
    USN-4902-1 20.04 (focal) on src python3-django URL Logo launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.5
    USN-4902-1 20.10 (groovy) on src python3-django URL Logo launchpad.net/ubuntu/+source/python-django/2:2.2.16-1ubuntu0.3