{"id":"SUSE-SU-2015:0694-1","summary":"Security update for python-Django","details":"\npython-Django has been updated to fix two vulnerabilities:\n\n    * URLs starting with control characters could have allowed XSS\n      (cross-site-scripting) attacks via user-supplied redirect URLs\n      (CVE-2015-2317)\n    * An infinite loop possibility could be triggered in the strip_tags()\n      function, which allowed denial of service attacks (CVE-2015-2316)\n\nSecurity Issues:\n\n    * CVE-2015-2316\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2316\u003e\n    * CVE-2015-2317\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2317\u003e\n\n","modified":"2026-03-11T05:59:04.061480Z","published":"2015-03-25T23:21:02Z","related":["CVE-2015-2316","CVE-2015-2317"],"upstream":["CVE-2015-2316","CVE-2015-2317"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20150694-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/923172"},{"type":"REPORT","url":"https://bugzilla.suse.com/923176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-2316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-2317"}],"schema_version":"1.7.5"}