Notes de publication de Django 1.9.8¶
July 18, 2016
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
July 18, 2016
Django 1.9.8 fixes a security issue and several bugs in 1.9.7.
Unsafe usage of JavaScript’s Element.innerHTML
could result in XSS in the
admin’s add/change related popup. Element.textContent
is now used to
prevent execution of the data.
The debug view also used innerHTML
. Although a security issue wasn’t
identified there, out of an abundance of caution it’s also updated to use
textContent
.
Hors ligne (Django 1.11) :
HTML |
PDF |
ePub
Offert par Read the Docs.