[Buildroot] [PATCH 1/1] package/python-django: security bump to version 3.2.5

Thomas Petazzoni thomas.petazzoni at bootlin.com
Thu Jul 15 20:43:59 UTC 2021


On Wed, 14 Jul 2021 10:50:44 +0200
Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:

> Fix CVE-2021-35042: Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5
> allows QuerySet.order_by SQL injection if order_by is untrusted input
> from a client of a web application.
> 
> https://www.djangoproject.com/weblog/2021/jul/01/security-releases
> https://docs.djangoproject.com/en/dev/releases/3.2.5
> 
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>
> ---
>  package/python-django/python-django.hash | 4 ++--
>  package/python-django/python-django.mk   | 4 ++--
>  2 files changed, 4 insertions(+), 4 deletions(-)

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com



More information about the buildroot mailing list