-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Jul 2022 14:24:42 +0200 Source: djangorestframework Architecture: source Version: 3.9.0-1+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Moritz Mühlenhoff <jmm@debian.org> Changes: djangorestframework (3.9.0-1+deb10u1) buster-security; urgency=medium . * Backport 4bb9a3c48427867ef1e46f7dee945a4c25a4f9b8 to fix cross-site scripting caused by disabled autoescaping in the default DRF Browsable API view templates (no CVE yet) * Backport ae649336b110afe21b9429f2554052f31a9dfaf9 to address CVE-2020-25626 Checksums-Sha1: 62f839e9ddde16e4f56c932ebd97ae29bc4313cf 2864 djangorestframework_3.9.0-1+deb10u1.dsc ffebd362ccf6bb9f5b546b96a027bc1c875dcc85 9581833 djangorestframework_3.9.0.orig.tar.gz 0610ad6e9d6bd610ef081ac89f4b8a61a5610f17 333036 djangorestframework_3.9.0-1+deb10u1.debian.tar.xz 4fa91f752321d1099e3cb52d65066f2a3a4006a3 9819 djangorestframework_3.9.0-1+deb10u1_source.buildinfo Checksums-Sha256: 5ac39f0119a77a40fcb13a68fc538032efd9da678c8e824a47f74c5de950e779 2864 djangorestframework_3.9.0-1+deb10u1.dsc 3a90018af9fdb6a92a66bda57b59730223bf0b4d293c409e03598afb50605b04 9581833 djangorestframework_3.9.0.orig.tar.gz 6b456011ca7c06bc6b00a8436b8365e5d813a963489e59fc495a914fbb9be2ac 333036 djangorestframework_3.9.0-1+deb10u1.debian.tar.xz 847e313fe39281267cad5dbbe650162d5bc25d6825d3437b89249cea25439da7 9819 djangorestframework_3.9.0-1+deb10u1_source.buildinfo Files: be85ac56540b0e6f6b7effa12e692780 2864 python optional djangorestframework_3.9.0-1+deb10u1.dsc a35d1e07e6aa79279ed15372dd4e4da7 9581833 python optional djangorestframework_3.9.0.orig.tar.gz 14727daa99e27a5e63614677c3191e4a 333036 python optional djangorestframework_3.9.0-1+deb10u1.debian.tar.xz d69e8d314cbe831e4c56ca84106e090b 9819 python optional djangorestframework_3.9.0-1+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmLaS3UACgkQEMKTtsN8 TjYAuw/9HJ51+3Z0FZmQG7FDBtHkhRXs70Z+zkLDG0tIRwcx6uUMJtxvWNoTjIDx T5u0T3sluH1QoJb5pt1eParvBDDwtcAsWJ/IIYAAQqPIJeY0Ej4QD0dPWK48zGKp jCzC8h+9ZK5TYSmPeDhAIWKzrdBy/iQ2j4I5N7qm/q9R9yyBnINZKY00YpggNCRR rhK0rAWdwqPQoqBRhASkBnVYRoOw6OxYDgvbX8vLZTHEN/lthFJuY0SbwFlt77K8 n6ZJTUPTV2PrKrgXuFO7eKzFLEya0KrmdLiuohj0jQthu1Px4n0XwPIem+DcudZi Onfj15nn6ZgIhH9h7Nsg9/IiQ95Tx8kgKgjiPXLNrxGR/xueoBSP9BZ5br+qLzVN p5oDyHd0NQ5NyR5VpltsfDd0dmCVDnICvRdYCkCZZfMN4bpGeRgMkOVlJxX+L3ND nmQ8y3tuQbe5eUXNT/F2EfQR5EKLNacGkzVk7OIQogV1Hy33d5QLXP+gXElbzZCJ DBDR2WpGEY6Vyr4eyDWVHUX5wE5K3Q6YKdtMAEl1guCiSGnlbGdvdtMSg4Q/+9Cj 3c8IZ5zrkEu8EYdhqM3lt8STEXjzBgggUbvyG647fswmh+r+6YIMzJHwcLm3HwfP Xm6lKS62dy/5N+zW7o1rE0DQpQbNQvKBCbTZ/Hsv6o5sbqg89GA= =wovQ -----END PGP SIGNATURE-----