You're receiving this message because you are on the security prenotification list for the Django web framework; information about this list can be found in our security policy [1]. In accordance with that policy, a set of security releases will be issued on Monday, March 4, 2024 around 900 UTC. This message contains descriptions of the issue, descriptions of the changes which will be made to Django, and the patches which will be applied to Django. ``django.utils.text.Truncator.words()`` method (with ``html=True``) and ``truncatewords_html`` template filter were subject to a potential regular expression denial-of-service attack using a suitably crafted string (follow up to CVE-2019-14232 and CVE-2023-43665). This issue has Moderate severity, according to the Django security policy [1]. Affected versions ================= * Django 5.0 * Django 4.2 * Django 3.2 Resolution ========== Included with this email are patches implementing the changes described above for each affected version of Django. On the release date, these patches will be applied to the Django development repository and the following releases will be issued along with disclosure of the issues: * Django 5.0.3 * Django 4.2.11 * Django 3.2.25 [1] https://www.djangoproject.com/security/
Created autotest-framework tracking bugs for this issue: Affects: epel-all [bug 2267656] Created python-django tracking bugs for this issue: Affects: epel-all [bug 2267657] Affects: fedora-all [bug 2267654] Created python-django16 tracking bugs for this issue: Affects: epel-all [bug 2267658] Created python-django3 tracking bugs for this issue: Affects: epel-all [bug 2267653] Affects: fedora-all [bug 2267655]
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:1640 https://access.redhat.com/errata/RHSA-2024:1640
This issue has been addressed in the following products: RHUI 4 for RHEL 8 Via RHSA-2024:1878 https://access.redhat.com/errata/RHSA-2024:1878
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:3781 https://access.redhat.com/errata/RHSA-2024:3781
This issue has been addressed in the following products: Red Hat Satellite 6.15 for RHEL 8 Via RHSA-2024:5662 https://access.redhat.com/errata/RHSA-2024:5662