pkgsrc/www/py-django2
adam 2c1ed8c30a py-django2: updated to 2.2.9
Django 2.2.9 fixes a security issue and a data loss bug in 2.2.8.

CVE-2019-19844: Potential account hijack via password reset form

By submitting a suitably crafted email address making use of Unicode characters, that compared equal to an existing user email when lower-cased for comparison, an attacker could be sent a password reset token for the matched account.

In order to avoid this vulnerability, password reset requests now compare the submitted email using the stricter, recommended algorithm for case-insensitive comparison of two identifiers from Unicode Technical Report 36, section 2.11.2(B)(2). Upon a match, the email containing the reset token will be sent to the email address on record rather than the submitted address.

Bugfixes
* Fixed a data loss possibility in SplitArrayField. When using with ArrayField(BooleanField()), all values after the first True value were marked as checked instead of preserving passed values
2019-12-19 13:40:36 +00:00
..
ALTERNATIVES py-django2: updated to 2.1.4 2018-12-03 19:04:16 +00:00
DESCR
distinfo py-django2: updated to 2.2.9 2019-12-19 13:40:36 +00:00
Makefile py-django2: updated to 2.2.9 2019-12-19 13:40:36 +00:00
MESSAGE
PLIST py-django2: updated to 2.2.3 2019-07-01 18:26:22 +00:00