Bug#1145999: bookworm-pu: package django-allauth/65.0.2-1+deb13u1

Pierre-Elliott Bécue <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <[email protected]>
Grmbl.

The worse is that I wrote everything by hand and my brain started to
work *after I finished*.

Pierre-Elliott Bécue <[email protected]> wrote on 28/08/2026 at 18:48:51+0200:

> Package: release.debian.org
> Severity: normal
> Tags: bookworm
> X-Debbugs-Cc: [email protected]
> Control: affects -1 + src:django-allauth
> User: [email protected]
> Usertags: pu
>
> Hello,
>
> [ Reason ]
> django-allauth has seen three CVEs reported, of which two I was able to
> find in the version released in stable.
>
> I cherry-picked the commits from upstream and built a new version
>
> [ Impact ]
> These CVEs are not major, if you believe these changes should not hit
> stable it is fine with me.

The second patch has a significant impact on production setups as it
changes the field to identify an account for Okta and NetIQ. This will
happen in forky anyway, but still, it requires a NEWS file and proper
information.

Here is a new debdiff.

> [ Tests ]
> Build and autopkgtest tests do cover the changed code
>
> [ Risks ]
> Changes are rather trivial.
>
> [ Checklist ]
>   [x] *all* changes are documented in the d/changelog
>   [x] I reviewed all changes and I approve them
>   [x] attach debdiff against the package in (old)stable
>   [x] the issue is verified as fixed in unstable
>
> [ Changes ]
>   * d/p/0004: fix(saml): prevent open redirect with IdP initiated SSO
>     (Closes: CVE-2026-27982, #1130044)
>
>     This change merely verifies that an url complies with the checks
>     done with is_safe_url, as defined in the DefaultAdapter in
>     allauth/account/adapter.py
>   * d/p/0005: fix(socialaccount): use ``sub`` in Okta/NetIQ
>     (Closes: CVE-2025-65431; #1123085)
>
>     This change moves from a mutable field to a non-mutable one
>     for the identifier used for the third party account in NetIQ and
>     Okta, which means that as soon as the user would change their
>     preferred_username, it would induce the creation of another account
>     upon relogin.
django-allauth.debdiff (application/octet-stream, 7.3 KB) - not displayed
signature.asc (application/pgp-signature, 853 B)
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEE5CQeth7uIW7ehIz87iFbn7jEWwsFAmqRwEkPHHBlYkBkZWJp
YW4ub3JnAAoJEO4hW5+4xFsLjDIQAJmRwfK9bkYSm7gmbH2ORmNqs36OHQXXvqCs
+a6zqRWaObXnr8XMb7J4Eukt9DZCW9QMcdINPmXfpotINmibqLw2JGaQVu5Ok3B/
zRbPUgnW1FRDLN62plT2rwg8dUl//4TzCTxb2w6p5NKZ8S4R6OzTyCdF6MC+vz18
u97Tj4ORtSCXSq1acS0Ty6B7AHpwSykppKqCOhz0tREaUvB/fS+lGEeH8JvxC3S8
7P/TucjriEaWcR24LVyLT+OxDCpPulK8pQw3IhxXvLgAYyGdR0udR3GlkvSOxwf6
vaZgDo87hlg7/jJ8zAYRpW7s+sRdoSE5OdVBlmvY+p1FX54jCgOhIO7CJVIFkXMI
3GsszW9Gzlym3JViXKgZzwA1bHAgqRHsYekKEdm4vIyBZaDLQ0LR3XLnnBIZNulV
ZZ3IxzEVu/BwLe6JKBja+VseSXHIksfD3nzDVJuqwODTJ76eUTZQyQs6xyGHu47m
Ru7SdQ/XRSE+fYqRCjEq4rHq21rkR9nu8ONxvgJ+2y1MLyAC8SjTM4zRlaIidhCd
6lJkbjxcFBxZjpK2dKgrjLU3/3eGDoZ74fVCy0cWlnG/qEBSV7WTRV8txYyctnjS
Pt0XBON5AF9/Ru4SK36fiGtUNFIDlfG0qAiIHL9phPZGjrEDVGpQ7UyPJARyFE3a
dOnM5L3u
=fG93
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.