FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

django -- multiple vulnerabilies

Affected packages
py27-django < 1.8.10
py32-django < 1.8.10
py33-django < 1.8.10
py34-django < 1.8.10
py35-django < 1.8.10
py27-django18 < 1.8.10
py32-django18 < 1.8.10
py33-django18 < 1.8.10
py34-django18 < 1.8.10
py35-django18 < 1.8.10
py27-django19 < 1.9.3
py32-django19 < 1.9.3
py33-django19 < 1.9.3
py34-django19 < 1.9.3
py35-django19 < 1.9.3
py27-django-devel <= 20150709,1
py32-django-devel <= 20150709,1
py33-django-devel <= 20150709,1
py34-django-devel <= 20150709,1
py35-django-devel <= 20150709,1

Details

VuXML ID f9e6c0d1-e4cc-11e5-b2bd-002590263bf5
Discovery 2016-03-01
Entry 2016-03-08

Tim Graham reports:

Malicious redirect and possible XSS attack via user-supplied redirect URLs containing basic auth

User enumeration through timing difference on password hasher work factor upgrade

References

CVE Name CVE-2016-2512
CVE Name CVE-2016-2513
URL https://www.djangoproject.com/weblog/2016/mar/01/security-releases/