Vulnerability Bulletins

DSA-3678 python-django - security update

   
Affected software Debian
 
Sergey Bobrov discovered that cookie parsing in Django and GoogleAnalytics interacted such a way that an attacker could set arbitrarycookies. This allows other malicious web sites to bypass theCross-Site Request Forgery (CSRF) protections built into Django.

More info:

https://www.debian.org/security/2016/dsa-3678