python-django: CVE-2020-13254 CVE-2020-13596

Related Vulnerabilities: CVE-2020-13254   CVE-2020-13596  

Debian Bug report logs - #962323
python-django: CVE-2020-13254 CVE-2020-13596

version graph

Reported by: "Chris Lamb" <lamby@debian.org>

Date: Sat, 6 Jun 2020 09:12:02 UTC

Severity: grave

Tags: security

Found in versions python-django/1:1.11.28-1~deb10u1, 2:2.2.12-1, python-django/1:1.10.7-2, python-django/1:1.10.7-2+deb9u7, python-django/1:1.10.7-2+deb9u8, python-django/1.7.11-1+deb8u3

Fixed in versions 2:2.2.13-1, 2:3.0.7-1, 1.7.11-1+deb8u9

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Python Modules Team <python-modules-team@lists.alioth.debian.org>:
Bug#962323; Package python-django. (Sat, 06 Jun 2020 09:12:04 GMT) (full text, mbox, link).


Acknowledgement sent to "Chris Lamb" <lamby@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Python Modules Team <python-modules-team@lists.alioth.debian.org>. (Sat, 06 Jun 2020 09:12:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "Chris Lamb" <lamby@debian.org>
To: submit@bugs.debian.org
Subject: python-django: CVE-2020-13254 CVE-2020-13596
Date: Sat, 06 Jun 2020 10:09:31 +0100
Package: python-django
Version: 1.7.11-1+deb8u3
X-Debbugs-CC: team@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for python-django.

CVE-2020-13254[0]:
| An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before
| 3.0.7. In cases where a memcached backend does not perform key
| validation, passing malformed cache keys could result in a key
| collision, and potential data leakage.


CVE-2020-13596[1]:
| An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before
| 3.0.7. Query parameters generated by the Django admin
| ForeignKeyRawIdWidget were not properly URL encoded, leading to a
| possibility of an XSS attack.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-13254
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13254
[1] https://security-tracker.debian.org/tracker/CVE-2020-13596
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13596


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-



Marked as fixed in versions 1.7.11-1+deb8u9. Request was from "Chris Lamb" <lamby@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 09:15:03 GMT) (full text, mbox, link).


Marked as fixed in versions 2:2.2.13-1. Request was from "Chris Lamb" <lamby@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 09:15:03 GMT) (full text, mbox, link).


Marked as fixed in versions 2:3.0.7-1. Request was from "Chris Lamb" <lamby@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 09:15:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian Python Modules Team <python-modules-team@lists.alioth.debian.org>:
Bug#962323; Package python-django. (Sat, 06 Jun 2020 09:24:02 GMT) (full text, mbox, link).


Acknowledgement sent to "Chris Lamb" <lamby@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Python Modules Team <python-modules-team@lists.alioth.debian.org>. (Sat, 06 Jun 2020 09:24:02 GMT) (full text, mbox, link).


Message #16 received at 962323@bugs.debian.org (full text, mbox, reply):

From: "Chris Lamb" <lamby@debian.org>
To: 962323@bugs.debian.org, team@security.debian.org
Subject: Re: python-django: CVE-2020-13254 CVE-2020-13596
Date: Sat, 06 Jun 2020 10:15:16 +0100
Hi,

> python-django: CVE-2020-13254 CVE-2020-13596

Security team, would you like an update for stretch and/or buster to
address these issues? It's fixed in sid, experimental as well as
jessie LTS. Bullseye is just pending migration time AFAICT.


Regards,

--
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-



Marked as found in versions 2:2.2.12-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 11:15:07 GMT) (full text, mbox, link).


Marked as found in versions python-django/1:1.11.28-1~deb10u1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 11:15:08 GMT) (full text, mbox, link).


Marked as found in versions python-django/1:1.10.7-2+deb9u8. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 11:15:08 GMT) (full text, mbox, link).


Marked as found in versions python-django/1:1.10.7-2+deb9u7. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 11:15:09 GMT) (full text, mbox, link).


Marked as found in versions python-django/1:1.10.7-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 06 Jun 2020 11:15:09 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sat Jun 6 13:39:49 2020; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.