mirror of
https://github.com/django/django.git
synced 2025-10-23 21:59:11 +00:00
Fixed CVE-2018-14574 -- Fixed open redirect possibility in CommonMiddleware.
This commit is contained in:
@@ -6,4 +6,6 @@ urlpatterns = [
|
||||
url(r'^noslash$', views.empty_view),
|
||||
url(r'^slash/$', views.empty_view),
|
||||
url(r'^needsquoting#/$', views.empty_view),
|
||||
# Accepts paths with two leading slashes.
|
||||
url(r'^(.+)/security/$', views.empty_view),
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user