diff options
author | rm <rm@FreeBSD.org> | 2016-03-06 04:28:58 +0800 |
---|---|---|
committer | rm <rm@FreeBSD.org> | 2016-03-06 04:28:58 +0800 |
commit | 0261b8a393f67f7841434a0db4ed9888db845742 (patch) | |
tree | 5200f5166852be95850d93e2edea3b9e62ddf934 /www | |
parent | 2abb1469fa942b390b77fcc00234e633d9670dbe (diff) | |
download | freebsd-ports-gnome-0261b8a393f67f7841434a0db4ed9888db845742.tar.gz freebsd-ports-gnome-0261b8a393f67f7841434a0db4ed9888db845742.tar.zst freebsd-ports-gnome-0261b8a393f67f7841434a0db4ed9888db845742.zip |
www/py-djblets: update to 0.9.2
Changelog [1]:
Fixed a Self-XSS vulnerability in the djblets.datagrid column headers.
A recently-discovered vulnerability in the datagrid templates allows an attacker
to generate a URL to any datagrid page containing malicious code in a column
sorting value. If the user visits that URL and then clicks that column, the code
will execute.
The cause of the vulnerability was due to a template not escaping user-provided
values.
This vulnerability was reported by Jose Carlos Exposito Bueno (0xlabs).
[1] https://www.reviewboard.org/docs/releasenotes/djblets/0.9.2/
With hat: python
Diffstat (limited to 'www')
-rw-r--r-- | www/py-djblets/Makefile | 2 | ||||
-rw-r--r-- | www/py-djblets/distinfo | 4 |
2 files changed, 3 insertions, 3 deletions
diff --git a/www/py-djblets/Makefile b/www/py-djblets/Makefile index 98e6c0f54aa3..9b67ee1d42dd 100644 --- a/www/py-djblets/Makefile +++ b/www/py-djblets/Makefile @@ -1,7 +1,7 @@ # $FreeBSD$ PORTNAME= djblets -PORTVERSION= 0.9.1 +PORTVERSION= 0.9.2 CATEGORIES= www python MASTER_SITES= CHEESESHOP PKGNAMEPREFIX= ${PYTHON_PKGNAMEPREFIX} diff --git a/www/py-djblets/distinfo b/www/py-djblets/distinfo index a91db1c65ac2..b1c524706528 100644 --- a/www/py-djblets/distinfo +++ b/www/py-djblets/distinfo @@ -1,2 +1,2 @@ -SHA256 (Djblets-0.9.1.tar.gz) = f0801b3b9b48b493ed70a389e917747fcca9e827a2a31ff7c7213ec72ad66b5d -SIZE (Djblets-0.9.1.tar.gz) = 332720 +SHA256 (Djblets-0.9.2.tar.gz) = 9df3db467ccc427d85f8a2f929557a884f9149fd32a96765c8854b1463a193f6 +SIZE (Djblets-0.9.2.tar.gz) = 332675 |