{"schema_version":"1.7.3","id":"openSUSE-SU-2018:2327-1","published":"2018-08-14T14:57:13Z","modified":"2025-05-07T18:10:03.935136Z","related":["CVE-2018-14574"],"upstream":["CVE-2018-14574"],"summary":"Security update for python-Django","details":"This update for python-Django to 1.11.15 fixes the following issues:\n\nThis security issue was fixed:\n\n- CVE-2018-14574: Prevent open redirect in django.middleware.common.CommonMiddleware (bsc#1102680).\n\nThese non-security issues were fixed:\n\n- Fixed WKBWriter.write() and write_hex() for empty polygons on GEOS 3.6.1+\n- Fixed a regression that could result in large memory usage when making edits\n  using ModelAdmin.list_editable\n- Fixed a regression where QuerySet.values() or values_list() after combining\n  an annotated and unannotated queryset with union(), difference(), or\n  intersection() crashed due to mismatching columns\n- Fixed crashes in django.contrib.admindocs when a view is a callable object,\n  such as django.contrib.syndication.views.Feed\n- Fixed a regression where altering a field with a unique constraint may drop\n  and rebuild more foreign keys than necessary\n- Fixed a regression where combining two annotated values_list() querysets with\n  union(), difference(), or intersection() crashed due to mismatching columns \n- Fixed a regression where an empty choice could be initially selected for the\n  SelectMultiple and CheckboxSelectMultiple widgets\n","affected":[{"package":{"name":"python-Django","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/python-Django&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.15-11.1"}]}],"ecosystem_specific":{"binaries":[{"python-Django":"1.11.15-11.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:2327-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GZTDVPYO7UI32QLDRAZCIZGUG4TWRQ22/#GZTDVPYO7UI32QLDRAZCIZGUG4TWRQ22"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14574"}]}