Comment 1 for bug 719031

Revision history for this message
James Bennett (ubernostrum) wrote : Re: [Bug 719031] [NEW] SECURITY - multiple vulnerabilities, upgrade needed to 1.2.5 or 1.1.4

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Guillaume Pratte wrote:
> See this link: http://www.djangoproject.com/weblog/2011/feb/08/security/
> No CVE seems to have been assigned yet.

As reported to us (Django), the following IDs have been assigned:

CVE-2011-0696 -- CSRF
CVE-2011-0697 -- file field XSS
CVE-2011-0698 -- directory traversal

- --
James Bennett
<email address hidden>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk1ZrLwACgkQNoTAwIyLKuG6nQCgou9wAa9lzkZmhT9zzPc1cPok
MEIAmgJd846BOUni/pLoiNu2mG1sgeai
=UtW5
-----END PGP SIGNATURE-----