VDB
Sign up
—

PYSEC-2021-369

Quick fix

PYSEC-2021-369 — django-unicorn: upgrade to the fixed version with the command below.

pip install --upgrade 'django-unicorn>=3a832a9e3f6455ddd3b87f646247269918ad10c6'

Details

The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-unicorn
Introduced in: 0Fixed in: 3a832a9e3f6455ddd3b87f646247269918ad10c6
Fixpip install --upgrade 'django-unicorn>=3a832a9e3f6455ddd3b87f646247269918ad10c6'

References