[3.8] py-django: AdminURLFieldWidget XSS (CVE-2019-12308)
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9,
and 2.2 before 2.2.2. The clickable Current URL
value displayed by the AdminURLFieldWidget displays the provided value
without validating it as a safe URL. Thus, an unvalidated
value stored in the database, or a value provided as a URL query
parameter payload, could result in an clickable JavaScript link.
Fixed In Version:
Django 2.2.2, Django 2.1.9, Django 1.11.21
References:
https://docs.djangoproject.com/en/dev/releases/1.11.21/
https://www.openwall.com/lists/oss-security/2019/06/03/2
Patch:
https://github.com/django/django/commit/c238701859a52d584f349cce15d56c8e8137c52b
(from redmine: issue id 10560, created on 2019-06-13, closed on 2019-06-26)
- Relations:
- parent #10557 (closed)
- Changesets:
- Revision ece47768 by Natanael Copa on 2019-06-25T21:08:37Z:
main/py-django: security upgrade to 1.11.21 (CVE-2019-12308)
fixes #10560