Path to this page:
Subject: CVS commit: pkgsrc/www/py-django4
From: Adam Ciarcinski
Date: 2024-03-04 16:48:16
Message id: 20240304154816.B3195FA29@cvs.NetBSD.org
Log Message:
py-django4: updated to 4.2.11
Django 4.2.11 fixes a security issue with severity “moderate” and a \
regression in 4.2.10.
CVE-2024-27351: Potential regular expression denial-of-service in \
django.utils.text.Truncator.words()
django.utils.text.Truncator.words() method (with html=True) and \
truncatewords_html template filter were subject to a potential regular \
expression denial-of-service attack using a suitably crafted string (follow up \
to CVE-2019-14232 and CVE-2023-43665).
Bugfixes
Fixed a regression in Django 4.2.10 where intcomma template filter could return \
a leading comma for string representation of floats.
Files: