1
0
mirror of https://github.com/django/django.git synced 2025-10-23 21:59:11 +00:00

Fixed XSS in admin's add/change related popup.

This is a security fix.
This commit is contained in:
Tim Graham
2016-07-06 15:41:06 -04:00
parent 767849b765
commit 93c538694e
5 changed files with 31 additions and 9 deletions

View File

@@ -2,9 +2,20 @@
Django 1.8.14 release notes
===========================
*Under development*
*July 18, 2016*
Django 1.8.14 fixes several bugs in 1.8.13.
Django 1.8.14 fixes a security issue and a bug in 1.8.13.
XSS in admin's add/change related popup
=======================================
Unsafe usage of JavaScript's ``Element.innerHTML`` could result in XSS in the
admin's add/change related popup. ``Element.textContent`` is now used to
prevent execution of the data.
The debug view also used ``innerHTML``. Although a security issue wasn't
identified there, out of an abundance of caution it's also updated to use
``textContent``.
Bugfixes
========

View File

@@ -2,9 +2,20 @@
Django 1.9.8 release notes
==========================
*Under development*
*July 18, 2016*
Django 1.9.8 fixes several bugs in 1.9.7.
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
XSS in admin's add/change related popup
=======================================
Unsafe usage of JavaScript's ``Element.innerHTML`` could result in XSS in the
admin's add/change related popup. ``Element.textContent`` is now used to
prevent execution of the data.
The debug view also used ``innerHTML``. Although a security issue wasn't
identified there, out of an abundance of caution it's also updated to use
``textContent``.
Bugfixes
========