Updated python-django package fixes a security vulnerability
Publication date: 14 Mar 2021Modification date: 14 Mar 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-23336
Description
Django contains a copy of urllib.parse.parse_qsl() which was added to backport some security fixes to prevent web cache poisoning. A further security fix has been issued recently such that parse_qsl() no longer allows using ; as a query parameter separator by default (CVE-2021-23336).
References
SRPMS
8/core
- python-django-3.1.7-1.mga8