USN-4975-2: Django vulnerability
7 June 2021
Several security issues were fixed in Django.
Releases
Packages
- python-django - High-level Python web development framework
Details
USN-4975-1 fixed a vulnerability in Django. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Rasmus Lerchedahl Petersen and Rasmus Wriedt Larsen discovered that Django
incorrectly handled path sanitation in admindocs. A remote attacker could
possibly use this issue to determine the existence of arbitrary files and
in certain configurations obtain their contents. (CVE-2021-33203)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
python-django
-
1.8.7-1ubuntu5.15+esm3
Available with Ubuntu Pro
-
python3-django
-
1.8.7-1ubuntu5.15+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-4975-1: python3-django, python-django-doc, python-django-common, python-django