package/python-django: security bump to version 3.0.12
authorPeter Korsgaard <peter@korsgaard.com>
Mon, 1 Feb 2021 12:55:57 +0000 (13:55 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 2 Feb 2021 15:35:01 +0000 (16:35 +0100)
commit28355e20fe3fc48bf9488e3a70a778c298b1f50b
tree7750405da13455d573e4df53eacefa21cdd71e3d
parent3a6fde69e1ccd250ea2bace34deaaf2140428f63
package/python-django: security bump to version 3.0.12

Fixes the following security issues:

CVE-2021-3281: Potential directory-traversal via archive.extract()

The django.utils.archive.extract() function, used by startapp --template and
startproject --template, allowed directory-traversal via an archive with
absolute paths or relative paths with dot segments.

For details, see the advisory:
https://www.djangoproject.com/weblog/2021/feb/01/security-releases/

Additionally, 3.0.11 fixed a regression:
https://docs.djangoproject.com/en/3.1/releases/3.0.11/

Update indentation in hash file (two spaces).

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/python-django/python-django.hash
package/python-django/python-django.mk