pkgsrc/www/py-django
adam 5c84a6129b py-django: updated to 1.11.21
Django 1.11.21 release notes

CVE-2019-12308: AdminURLFieldWidget XSS

The clickable “Current URL” link generated by AdminURLFieldWidget displayed the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.

AdminURLFieldWidget now validates the provided value using URLValidator before displaying the clickable link. You may customise the validator by passing a validator_class kwarg to AdminURLFieldWidget.__init__(), e.g. when using formfield_overrides.
2019-06-03 12:33:00 +00:00
..
ALTERNATIVES py-django: updated to 1.11.17 2018-12-03 18:59:35 +00:00
DESCR
distinfo py-django: updated to 1.11.21 2019-06-03 12:33:00 +00:00
Makefile py-django: updated to 1.11.21 2019-06-03 12:33:00 +00:00
MESSAGE
PLIST py-django: updated to 1.11.17 2018-12-03 18:59:35 +00:00