Vulnerability Bulletins |
DSA-3678 python-django - security update |
|
| Affected software | Debian |
|
Sergey Bobrov discovered that cookie parsing in Django and GoogleAnalytics interacted such a way that an attacker could set arbitrarycookies. This allows other malicious web sites to bypass theCross-Site Request Forgery (CSRF) protections built into Django. More info: https://www.debian.org/security/2016/dsa-3678 |
|






