package/python-django: security bump to version 3.0.1
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 20 Dec 2019 08:19:17 +0000 (09:19 +0100)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sat, 21 Dec 2019 22:08:18 +0000 (23:08 +0100)
commit0ea753f8d3fbbb88629b82c1befbd1fc224b59bf
treeb5cdf838d054116c10d00d13e3ed3b41d07eb96a
parentb5784520ccf89ce23b8a2f74b08f61f57b989a75
package/python-django: security bump to version 3.0.1

Fixes the following security vulnerability:

- CVE-2019-19844: Potential account hijack via password reset form
  By submitting a suitably crafted email address making use of Unicode
  characters, that compared equal to an existing user email when lower-cased
  for comparison, an attacker could be sent a password reset token for the
  matched account

In addition, a number of bugs have been fixed.  For details, see the release
notes:
https://docs.djangoproject.com/en/dev/releases/3.0.1/

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/python-django/python-django.hash
package/python-django/python-django.mk