SUSE-SU-2015:1109-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 30 Mar 2015, 09:04
Last modified:04 Feb 2026, 03:52

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Mar 2015, 09:04
Published
Vulnerability first disclosed
04 Feb 2026, 03:52
Last Modified
Vulnerability information updated

Description

Security update for python-Django python-django was updated to 1.6.11 to fix security issues and non-security bugs. The following vulnerabilities were fixed: * Made is_safe_url() reject URLs that start with control characters to mitigate possible XSS attack via user-supplied redirect URLs (bnc#923176, CVE-2015-2317) * Fixed an infinite loop possibility in strip_tags() (bnc#923172, CVE-2015-2316) * WSGI header spoofing via underscore/dash conflation (bnc#913053, CVE-2015-0219) * Mitigated possible XSS attack via user-supplied redirect URLs * Denial-of-service attack against ``django.views.static.serve`` (bnc#913056, CVE-2015-0221) * Database denial-of-service with ``ModelMultipleChoiceField`` (bnc#913055, CVE-2015-0222) The update also contains fixes for non-security bugs, functional and stability issues.

Affected Systems

  • susepython-Django&distro=SUSE Enterprise Storage 1.0

    < 1.6.11-4.1

References (11)