VDB
Sign up
—

PYSEC-2012-2

Quick fix

PYSEC-2012-2 — django: upgrade to the fixed version with the command below.

pip install --upgrade 'django>=1.3.2'

Details

The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django
Introduced in: 0Fixed in: 1.3.2
Fixpip install --upgrade 'django>=1.3.2'

References