mirror of
https://github.com/django/django.git
synced 2025-10-23 21:59:11 +00:00
Fixed XSS in admin's add/change related popup.
This is a security fix.
This commit is contained in:
@@ -2,9 +2,20 @@
|
||||
Django 1.8.14 release notes
|
||||
===========================
|
||||
|
||||
*Under development*
|
||||
*July 18, 2016*
|
||||
|
||||
Django 1.8.14 fixes several bugs in 1.8.13.
|
||||
Django 1.8.14 fixes a security issue and a bug in 1.8.13.
|
||||
|
||||
XSS in admin's add/change related popup
|
||||
=======================================
|
||||
|
||||
Unsafe usage of JavaScript's ``Element.innerHTML`` could result in XSS in the
|
||||
admin's add/change related popup. ``Element.textContent`` is now used to
|
||||
prevent execution of the data.
|
||||
|
||||
The debug view also used ``innerHTML``. Although a security issue wasn't
|
||||
identified there, out of an abundance of caution it's also updated to use
|
||||
``textContent``.
|
||||
|
||||
Bugfixes
|
||||
========
|
||||
|
||||
@@ -2,9 +2,20 @@
|
||||
Django 1.9.8 release notes
|
||||
==========================
|
||||
|
||||
*Under development*
|
||||
*July 18, 2016*
|
||||
|
||||
Django 1.9.8 fixes several bugs in 1.9.7.
|
||||
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
|
||||
|
||||
XSS in admin's add/change related popup
|
||||
=======================================
|
||||
|
||||
Unsafe usage of JavaScript's ``Element.innerHTML`` could result in XSS in the
|
||||
admin's add/change related popup. ``Element.textContent`` is now used to
|
||||
prevent execution of the data.
|
||||
|
||||
The debug view also used ``innerHTML``. Although a security issue wasn't
|
||||
identified there, out of an abundance of caution it's also updated to use
|
||||
``textContent``.
|
||||
|
||||
Bugfixes
|
||||
========
|
||||
|
||||
Reference in New Issue
Block a user