[1.7.x] Made is_safe_url() reject URLs that start with control characters.
This is a security fix; disclosure to follow shortly.
Showing
- django/utils/http.py 8 additions, 2 deletionsdjango/utils/http.py
- docs/releases/1.4.20.txt 19 additions, 0 deletionsdocs/releases/1.4.20.txt
- docs/releases/1.6.11.txt 19 additions, 0 deletionsdocs/releases/1.6.11.txt
- docs/releases/1.7.7.txt 19 additions, 0 deletionsdocs/releases/1.7.7.txt
- tests/utils_tests/test_http.py 3 additions, 1 deletiontests/utils_tests/test_http.py
Loading
Please register or sign in to comment