{"schema_version":"1.7.3","id":"SUSE-SU-2019:3127-1","published":"2019-11-29T16:21:37Z","modified":"2026-02-04T04:13:48.696087Z","related":["CVE-2019-12781","CVE-2019-3498"],"upstream":["CVE-2019-12781","CVE-2019-3498"],"summary":"Security update for python-Django","details":"This update for python-Django fixes the following issues:\n\n- CVE-2019-12781: Added incorrect HTTP detection with reverse-proxy \n  connecting via HTTPS (bsc#1139945).\n- CVE-2019-3498: Fixed a content spoofing via crafted URL in the default \n  404 page (bsc#1120932).\n","affected":[{"package":{"name":"python-Django","ecosystem":"SUSE:Enterprise Storage 5","purl":"pkg:rpm/suse/python-Django&distro=SUSE%20Enterprise%20Storage%205"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.11-6.10.1"}]}],"ecosystem_specific":{"binaries":[{"python-Django":"1.6.11-6.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:3127-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20193127-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1120932"},{"type":"REPORT","url":"https://bugzilla.suse.com/1139945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12781"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-3498"}]}