Advisories ยป MGASA-2021-0135

Updated python-django package fixes a security vulnerability

Publication date: 14 Mar 2021
Modification date: 14 Mar 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-23336

Description

Django contains a copy of urllib.parse.parse_qsl() which was added to backport
some security fixes to prevent web cache poisoning. A further security fix has
been issued recently such that parse_qsl() no longer allows using ; as a query
parameter separator by default (CVE-2021-23336).
                

References

SRPMS

8/core