HendrikPN / scigym-api

API for the scigym library to curate scientific reinforcement learning environments.
0 stars 2 forks source link

security alert: outdated django #21

Closed HendrikPN closed 4 years ago

HendrikPN commented 5 years ago

An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.

HendrikPN commented 4 years ago

this issue was closed by #37