LWN.net Logo

django: cross-site request forgery

Package(s):django CVE #(s):
Created:September 4, 2008 Updated:September 10, 2008
Description: From the Mandriva alert: A cross-site request forgery vulnerability was discovered in Django that, if exploited, could be used to perform unrequested deletion or modification of data. Updated versions of Django will now discard posts from users whose sessions have expired, so data will need to be re-entered in these cases.
Alerts:
Mandriva MDVSA-2008:185 2007-09-03
Fedora FEDORA-2008-7288 2008-09-05
Fedora FEDORA-2008-7672 2008-09-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds