<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-openembedded.git/meta-python/recipes-devtools/python/python3-django_2.2.25.bb, branch mickledore-next</title>
<subtitle>Mirror of git.openembedded.org/meta-openembedded</subtitle>
<id>https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-openembedded.git/atom?h=mickledore-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/'/>
<updated>2022-01-10T18:34:34+00:00</updated>
<entry>
<title>python3-django: upgrade 2.2.25 -&gt; 2.2.26</title>
<updated>2022-01-10T18:34:34+00:00</updated>
<author>
<name>Trevor Gamblin</name>
<email>trevor.gamblin@windriver.com</email>
</author>
<published>2022-01-07T18:52:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=280195a1098f7b18c0d3eea1ff8da987f6ff523a'/>
<id>urn:sha1:280195a1098f7b18c0d3eea1ff8da987f6ff523a</id>
<content type='text'>
2.2.26 provides fixes for three CVEs:

CVE-2021-45115
CVE-2021-45116
CVE-2021-45452

https://docs.djangoproject.com/en/4.0/releases/2.2.26/

Signed-off-by: Trevor Gamblin &lt;trevor.gamblin@windriver.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Trevor Gamblin &lt;trevor.gamblin@windriver.com&gt;
</content>
</entry>
<entry>
<title>python3-django: upgrade 2.2.24 -&gt; 2.2.25</title>
<updated>2021-12-16T16:14:04+00:00</updated>
<author>
<name>Xu Huan</name>
<email>xuhuan.fnst@fujitsu.com</email>
</author>
<published>2021-12-15T09:48:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-openembedded.git/commit/?id=eaacb6321cdcd511dddbcffaaf664eff1b384aa5'/>
<id>urn:sha1:eaacb6321cdcd511dddbcffaaf664eff1b384aa5</id>
<content type='text'>
changelog:
================================================================================

Django 2.2.25 fixes a security issue with severity "low" in 2.2.24.

CVE-2021-44420: Potential bypass of an upstream access control based on URL paths
=================================================================================

HTTP requests for URLs with trailing newlines could bypass an upstream access
control based on URL paths.

Signed-off-by: Xu Huan &lt;xuhuan.fnst@fujitsu.com&gt;
Signed-off-by: Khem Raj &lt;raj.khem@gmail.com&gt;
Signed-off-by: Trevor Gamblin &lt;trevor.gamblin@windriver.com&gt;
</content>
</entry>
</feed>
