Debian Security Advisory

DSA-3622-1 python-django -- security update

Date Reported:
18 Jul 2016
Affected Packages:
python-django
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-6186.
More information:

It was discovered that Django, a high-level Python web development framework, is prone to a cross-site scripting vulnerability in the admin's add/change related popup.

For the stable distribution (jessie), this problem has been fixed in version 1.7.7-1+deb8u5.

We recommend that you upgrade your python-django packages.