Path to this page:
Subject: CVS commit: pkgsrc/www/py-django
From: Adam Ciarcinski
Date: 2019-06-03 14:33:00
Message id: 20190603123300.B4417FBF4@cvs.NetBSD.org
Log Message:
py-django: updated to 1.11.21
Django 1.11.21 release notes
CVE-2019-12308: AdminURLFieldWidget XSS
The clickable “Current URL” link generated by AdminURLFieldWidget displayed \
the provided value without validating it as a safe URL. Thus, an unvalidated \
value stored in the database, or a value provided as a URL query parameter \
payload, could result in an clickable JavaScript link.
AdminURLFieldWidget now validates the provided value using URLValidator before \
displaying the clickable link. You may customise the validator by passing a \
validator_class kwarg to AdminURLFieldWidget.__init__(), e.g. when using \
formfield_overrides.
Files: