Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Ubuntu 24.04 LTS Security Advisory USN-6987-1 Critical: Django Issues

ubuntu
Calendar Grey September 3, 2024
Scroller Ubuntu
Python web framework vulnerabilities mitigated in the Ubuntu security advisory from September 2024, with critical patches distributed for various long-term support versions.
Several security issues were fixed in Django.

Summary

Several security issues were fixed in Django.

Software Description:

- python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled certain inputs.

An attacker could possibly use this issue to cause a denial of service.

(CVE-2024-45230)

It was discovered that Django incorrectly handled certain email sending

failures. A remote attacker could possibly use this issue to enumerate

user emails by issuing password reset requests and observing the outcomes.

(CVE-2024-45231)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  python3-django                  3:4.2.11-1ubuntu1.3

Ubuntu 22.04 LTS
  python3-django                  2:3.2.12-2ubuntu1.14

Ubuntu 20.04 LTS
  python3-django                  2:2.2.12-1ubuntu0.25

Ubuntu 18.04 LTS
  python-django                   1:1.11.11-1ubuntu1.21+esm7
                                  Available with Ubuntu Pro
  python3-django                  1:1.11.11-1ubuntu1.21+esm7
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6987-1

CVE-2024-45230, CVE-2024-45231

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6987-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.