This update for python-djangorestframework fixes the following issues:
- CVE-2024-21520: Fixed improper input sanitization before splitting and
joining with 'br' tags (boo#1227077)
- Tests can be run only on (newer) python311 stack
- Make it at least installable on python3 stack (no guarantees for it to
run)
- Use sle15allpythons to get the Python 3.6 packages (jsc#PED-8919)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-38=1
- openSUSE Backports SLE-15-SP7 (noarch):
python3-djangorestframework-3.14.0-bp157.2.3.1
python311-djangorestframework-3.14.0-bp157.2.3.1
https://www.suse.com/security/cve/CVE-2024-21520.html
https://bugzilla.suse.com/1227077
Get the latest Linux and open source security news straight to your inbox.