—
PYSEC-2010-12
Quick fix
PYSEC-2010-12 — django: upgrade to the fixed version with the command below.
pip install --upgrade 'django>=1.2.2'Details
Cross-site scripting (XSS) vulnerability in Django 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via a csrfmiddlewaretoken (aka csrf_token) cookie.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://bugzilla.redhat.com/show_bug.cgi?id=632239[REPORT]
- http://marc.info/?l=oss-security&m=128403961700444&w=2[WEB]
- http://www.djangoproject.com/weblog/2010/sep/08/security-release/[ARTICLE]
- http://www.securityfocus.com/bid/43116[WEB]
- http://www.ubuntu.com/usn/USN-1004-1[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61729[WEB]
- https://github.com/advisories/GHSA-fxpg-gg9g-76gj[ADVISORY]