QID 981145
QID 981145: Python (pip) Security Update for django (GHSA-9r8w-6x8c-6jr9)
In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9r8w-6x8c-6jr9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-9r8w-6x8c-6jr9 -
github.com/advisories/GHSA-9r8w-6x8c-6jr9
CVEs related to QID 981145
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9r8w-6x8c-6jr9 | django |
|