pkgsrc/www/py-django
adam 21cc5acead py-django: updated to 1.11.5
1.11.5:
Fix CVE-2018-14574: Open redirect possibility in CommonMiddleware

If the CommonMiddleware and the APPEND_SLASH setting are both enabled, and if the project has a URL pattern that accepts any path ending in a slash (many content management systems have such a pattern), then a request to a maliciously crafted URL of that site could lead to a redirect to another site, enabling phishing and other attacks.

CommonMiddleware now escapes leading slashes to prevent redirects to other domains.
2018-08-02 14:02:21 +00:00
..
patches py-django: updated to 1.11.4 2018-07-03 06:42:27 +00:00
ALTERNATIVES
DESCR
distinfo py-django: updated to 1.11.5 2018-08-02 14:02:21 +00:00
Makefile py-django: updated to 1.11.5 2018-08-02 14:02:21 +00:00
MESSAGE
PLIST py-django: updated to 1.11.8 2017-12-04 14:23:00 +00:00