[Buildroot] [PATCH] package/python-django: security bump to version 3.0.3

Thomas Petazzoni thomas.petazzoni at bootlin.com
Mon Feb 3 11:33:51 UTC 2020


On Mon,  3 Feb 2020 12:28:21 +0100
Peter Korsgaard <peter at korsgaard.com> wrote:

> Fixes the following security issues:
> 
> - CVE-2020-7471: Potential SQL injection via StringAgg(delimiter)
>   django.contrib.postgres.aggregates.StringAgg aggregation function was
>   subject to SQL injection, using a suitably crafted delimiter.
> 
> For more details, see the advisory:
> https://www.djangoproject.com/weblog/2020/feb/03/security-releases/
> 
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
> ---
>  package/python-django/python-django.hash | 4 ++--
>  package/python-django/python-django.mk   | 4 ++--
>  2 files changed, 4 insertions(+), 4 deletions(-)

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


More information about the buildroot mailing list