QID 198614

Date Published: 2022-01-06

QID 198614: Ubuntu Security Notification for Django Vulnerabilities (USN-5204-1)

Django incorrectly handled evaluatingsubmitted passwords.
Django incorrectly handled the dictsorttemplate filter.
Django incorrectly handled certain filenames.

A remote attacker could possibly use this issue toconsume resources, resulting in a denial of service.
A remote attacker could possibly use this issue to obtainsensitive information.
A remote attacker could possibly use this issue to save files toarbitrary filesystem locations.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5204-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198614

    Software Advisories
    Advisory ID Software Component Link
    USN-5204-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5204-1