The Vulnerability History Project
Vulnerabilities
Insights
Curate
Tags
All
Projects
CWEs
Languages
Lessons
Severities
Subsystems
More
News
Projects We Study
How to Contribute
By the Numbers
About Us
Toggle Theme
Warning: Our website does not support Internet Explorer, please use Edge instead.
[1.9.x] Fixed CVE-2016-2512 -- Prevented spoofing is_safe_url() with basic auth.
This is a security fix.
by
Clayton the Whippet 2016-02-22 21:50:23 UTC
commit fc6d147a63f89795dbcdecb0559256470fff4380
Django
Fix
CVE-2016-2512
VCC
Unsafe-URLS's CVE-2017-7233
django/utils/http.py
+2
-6
docs/releases/1.8.10.txt
-16
docs/releases/1.9.3.txt
-16
tests/utils_tests/test_http.py
-12
expand_less