The Vulnerability History Project
Vulnerabilities
Insights
Curate
Tags
All
Projects
CWEs
Languages
Lessons
Severities
Subsystems
More
News
Projects We Study
How to Contribute
By the Numbers
About Us
Toggle Theme
Warning: Our website does not support Internet Explorer, please use Edge instead.
[1.4.x] Made is_safe_url() reject URLs that start with control characters.
This is a security fix; disclosure to follow shortly.
by
Lindsey the Elephant Seal 2015-03-10 00:05:13 UTC
commit 2342693b31f740a422abf7267c53b4e7bc487c1b
Django
Fix
URL Not Validated CVE-2015-2317
django/utils/http.py
+1
-8
docs/releases/1.4.20.txt
-19
tests/regressiontests/utils/http.py
+1
-3
expand_less