From a1af4c78e8ccb0adb89ebcc94e0c265b7062e00e Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 4 Jan 2022 13:35:47 +0100 Subject: Record commits for three python-django issues --- data/CVE/2021.list | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index f1a164712b..7f7ea967d8 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -1668,6 +1668,8 @@ CVE-2021-45452 [Potential directory-traversal via Storage.save()] RESERVED - python-django (bug #1003113) NOTE: https://www.djangoproject.com/weblog/2022/jan/04/security-releases/ + NOTE: https://github.com/django/django/commit/8d2f7cff76200cbd2337b2cf1707e383eb1fb54b (3.2.11) + NOTE: https://github.com/django/django/commit/4cb35b384ceef52123fc66411a73c36a706825e1 (2.2.26) CVE-2021-4150 [Block subsystem mishandles reference counts] RESERVED - linux 5.15.3-1 @@ -2438,10 +2440,14 @@ CVE-2021-45116 [Potential information disclosure in dictsort template filter] RESERVED - python-django (bug #1003113) NOTE: https://www.djangoproject.com/weblog/2022/jan/04/security-releases/ + NOTE: https://github.com/django/django/commit/c7fe895bca06daf12cc1670b56eaf72a1ef27a16 (3.2.11) + NOTE: https://github.com/django/django/commit/c9f648ccfac5ab90fb2829a66da4f77e68c7f93a (2.2.26) CVE-2021-45115 [Denial-of-service possibility in UserAttributeSimilarityValidator] RESERVED - python-django (bug #1003113) NOTE: https://www.djangoproject.com/weblog/2022/jan/04/security-releases/ + NOTE: https://github.com/django/django/commit/a8b32fe13bcaed1c0b772fdc53de84abc224fb20 (3.2.11) + NOTE: https://github.com/django/django/commit/2135637fdd5ce994de110affef9e67dffdf77277 (2.2.26) CVE-2021-45106 RESERVED CVE-2021-44463 -- cgit v1.2.3