—
PYSEC-2023-211
Quick fix
PYSEC-2023-211 — django-grappelli: upgrade to the fixed version with the command below.
pip install --upgrade 'django-grappelli>=4ca94bcda0fa2720594506853d85e00c8212968f'Details
views/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but this does not consider a protocol-relative URL (e.g., //example.com) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/django-grappelli
Introduced in:
0Fixed in: 4ca94bcda0fa2720594506853d85e00c8212968fFix
pip install --upgrade 'django-grappelli>=4ca94bcda0fa2720594506853d85e00c8212968f'References
- https://github.com/sehmaschine/django-grappelli/commit/4ca94bcda0fa2720594506853d85e00c8212968f[FIX]
- https://github.com/sehmaschine/django-grappelli/pull/976[WEB]
- https://github.com/sehmaschine/django-grappelli/compare/2.15.1...2.15.2[WEB]
- https://github.com/sehmaschine/django-grappelli/issues/975[REPORT]
- https://github.com/advisories/GHSA-9x43-5qcq-h79q[ADVISORY]