Debian Security Advisory
DSA-3204-1 python-django -- security update
- Date Reported:
- 24 Mar 2015
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 780873.
In Mitre's CVE dictionary: CVE-2015-2317.
- More information:
Daniel Chatfield discovered that python-django, a high-level Python web development framework, incorrectly handled user-supplied redirect URLs. A remote attacker could use this flaw to perform a cross-site scripting attack.
For the stable distribution (wheezy), this problem has been fixed in version 1.4.5-1+deb7u11.
For the unstable distribution (sid), this problem has been fixed in version 1.7.7-1.
We recommend that you upgrade your python-django packages.