ArchLinux: 201503-7: python2-django python-django - cross site scripting
Summary
XSS attack via properties in ModelAdmin.readonly_fields
Resolution
Upgrade to 1.7.6-1.
# pacman -Syu "python2-django>=1.7.6.-1"
# pacman -Syu "python-django>=1.7.6-1"
References
https://www.djangoproject.com/weblog/2015/mar/09/security-releases/ https://security-tracker.debian.org/tracker/CVE-2015-2241 https://bugs.archlinux.org/task/44122
Workaround
None.