Bug#929927: python-django: CVE-2019-12308: AdminURLFieldWidget XSS

2019-06-04 Thread Luke Faraone
Yep, planning on tackling this evening. (PDT) Per discussion with Security Team a DSA isn't warranted for this issue. On Tue, 4 Jun 2019 at 10:11, Chris Lamb wrote: > [Adding lfara...@debian.org to CC] > > Salvatore Bonaccorso wrote > > > CVE-2019-12308[0]: > > AdminURLFieldWidget XSS > > > >

Bug#929927: python-django: CVE-2019-12308: AdminURLFieldWidget XSS

2019-06-04 Thread Chris Lamb
[Adding lfara...@debian.org to CC] Salvatore Bonaccorso wrote > CVE-2019-12308[0]: > AdminURLFieldWidget XSS > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0]

Bug#929927: python-django: CVE-2019-12308: AdminURLFieldWidget XSS

2019-06-03 Thread Salvatore Bonaccorso
Source: python-django Version: 1:1.11.20-1 Severity: important Tags: security upstream Control: found -1 2:2.2.1-1 Hi, The following vulnerability was published for python-django. CVE-2019-12308[0]: AdminURLFieldWidget XSS If you fix the vulnerability please also make sure to include the CVE