VDB
Sign up
—

PYSEC-2014-79

Quick fix

PYSEC-2014-79 — djblets: upgrade to the fixed version with the command below.

pip install --upgrade 'djblets>=50000d0bbb983fa8c097b588d06b64df8df483bd'

Details

Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djblets
Introduced in: 0Fixed in: 50000d0bbb983fa8c097b588d06b64df8df483bd
Fixpip install --upgrade 'djblets>=50000d0bbb983fa8c097b588d06b64df8df483bd'

References