Path to this page:
Subject: CVS commit: pkgsrc/www/py-django
From: Wen Heping
Date: 2016-10-21 04:19:46
Message id: 20161021021946.8DC0DFBD2@cvs.NetBSD.org
Log Message:
Update to 1.9.10(security update)
Upstream changes:
Django 1.9.10 release notes
September 26, 2016
Django 1.9.10 fixes a security issue in 1.9.9.
CSRF protection bypass on a site with Google Analytics
An interaction between Google Analytics and Django's cookie parsing could allow \
an attacker to set arbitrary cookies leading to a bypass of CSRF protection.
The parser for request.COOKIES is simplified to better match the behavior of \
browsers and to mitigate this attack. request.COOKIES may now contain cookies \
that are invalid according to RFC 6265 but are possible to set via \
document.cookie.
Files: