Your message dated Wed, 03 May 2023 17:09:38 +0000
with message-id <[email protected]>
and subject line Bug#1035467: fixed in python-django 3:3.2.19-1
has caused the Debian Bug report #1035467,
regarding python-django: CVE-2023-31047
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1035467: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035467
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: python-django
Version: 1:1.11.29-1+deb10u7
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerability was published for python-django:

  CVE-2023-31047: Potential bypass of validation when uploading
  multiple files using one form field

  Uploading multiple files using one form field has never been
  supported by forms.FileField or forms.ImageField as only the last
  uploaded file was validated. Unfortunately, Uploading multiple files
  topic suggested otherwise.

  In order to avoid the vulnerability, ClearableFileInput and
  FileInput` form widgets now raise ValueError when the multiple HTML
  attribute is set on them. To prevent the exception and keep the old
  behavior, set allow_multiple_selected to True.

  For more details on using the new attribute and handling of multiple
  files through a single field, see Uploading multiple files.

    — <https://www.djangoproject.com/weblog/2023/may/03/security-releases/>


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      [email protected] / chris-lamb.co.uk
       `-

--- End Message ---
--- Begin Message ---
Source: python-django
Source-Version: 3:3.2.19-1
Done: Chris Lamb <[email protected]>

We believe that the bug you reported is fixed in the latest version of
python-django, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Lamb <[email protected]> (supplier of updated python-django package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 03 May 2023 09:32:59 -0700
Source: python-django
Built-For-Profiles: nocheck
Architecture: source
Version: 3:3.2.19-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Chris Lamb <[email protected]>
Closes: 1035467
Changes:
 python-django (3:3.2.19-1) unstable; urgency=medium
 .
   * New upstream security release.
   * CVE-2023-31047: Prevent a potential bypass of validation when uploading
     multiple files using one form field.
 .
     Uploading multiple files using one form field has never been supported by
     forms.FileField or forms.ImageField as only the last uploaded file was
     validated. Unfortunately, Uploading multiple files topic suggested
     otherwise. In order to avoid the vulnerability, the ClearableFileInput and
     FileInput form widgets now raise ValueError when the multiple HTML
     attribute is set on them. To prevent the exception and keep the old
     behavior, set the allow_multiple_selected attribute to True.
 .
     For more details on using the new attribute and handling of multiple files
     through a single field, see:
 .
       
<https://docs.djangoproject.com/en/stable/topics/http/file-uploads/#uploading-multiple-files>
 .
     (Closes: #1035467)
 .
   * Bump Standards-Version to 4.6.2.
Checksums-Sha1:
 77feaf7b11ab9338b75663c4808bc75ed253a9f6 2807 python-django_3.2.19-1.dsc
 42f62327acc78f37f69cba058232fbfd7d8c77cd 9832772 
python-django_3.2.19.orig.tar.gz
 f6f403f34e4d23073ba91838fcc96dd148564566 38032 
python-django_3.2.19-1.debian.tar.xz
 8cf1f34c917df81e05d357f08318bad8fe7c9595 7954 
python-django_3.2.19-1_amd64.buildinfo
Checksums-Sha256:
 3b00f2009508a960f1eccae8762667b6c4b4097673bb9d50c8f007bb4e36d8a5 2807 
python-django_3.2.19-1.dsc
 031365bae96814da19c10706218c44dff3b654cc4de20a98bd2d29b9bde469f0 9832772 
python-django_3.2.19.orig.tar.gz
 924c91276b40c03aa3dacd397966849000599121d8e4d8398b6078eab1153698 38032 
python-django_3.2.19-1.debian.tar.xz
 a8b01eb05d5feaaddd87b62baa7b4106cbf21db02a915cc316f689b3ac8f5266 7954 
python-django_3.2.19-1_amd64.buildinfo
Files:
 4b3bdcee47d7b3eec43f2a9908a6c13b 2807 python optional 
python-django_3.2.19-1.dsc
 d84f0b8669678fea14579d7400a521e2 9832772 python optional 
python-django_3.2.19.orig.tar.gz
 067806366ba9dc958fcc7e98659b95a5 38032 python optional 
python-django_3.2.19-1.debian.tar.xz
 32d650485b0743773b1484c525b41d5d 7954 python optional 
python-django_3.2.19-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmRSjvUACgkQHpU+J9Qx
HlgHaA/+NaPOoLi/zC/SDsp81SOzwjHYRAUQHl+nLbKC6Xcy7B0YgI22ECMunTyk
9BZh2JlOCSTzIUO3pM/zWyIMSwRs7QqkmCfMbbJFgdM8TT8BKywBv6XT1iUXwEIM
DQ0yZwjVwXXFK+jrq/l1Ngypj+2n4/Nhwaxe6U4IguZiVHOgXx0YY/0np9AC5mYw
fdvsAAGKG6xQQIOpE95KS6NzofDj+49aue5oJ3AO4bMf+aIRdeUVN5vjaqF4NBEU
fS2/mmFqzVOExSOMfXzoq8ij2XvX9/XPPxqkp3gHDhTadp1rrlOFI8/qYxJaGV6l
jeK+Fndt7Ne3xjMS+23g79OOAfJNfckYTS7RcNw1JrtdhS761xzycR9sCYzfU+lD
mRvlocPx3QtSws8vlA8t2jGS+CPfWzBUuJW29awqUoP/HwdCEa3mC7khmOKFUboY
VQhjypKQRRb2NVpQ+4Jzw3SDNc0UTb68fgN1nRKmAyCWCF90EcamS0il40DUNX2x
mhJwS+dRABTzcR5SaTu9Eb9bCAFC7lCk4aSI9CNQUuxpa2YmLRLiKSl/F6vKSGEK
XUmMt82vhyRHpRIzuOlAg3DThTxVRszGwtjwdpk8XECPFpYJnYHq5thris9E1Y9F
Np1rbgNfVE9LA36fsUScozCAB95sVprFn0xs1aTIpxpVvkm5TVU=
=2JQv
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to