Google Groups Home
Help | Sign in
ANN: User-creation hole fixed in Django development (Subversion) version
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  1 message - Collapse all
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Adrian Holovaty  
View profile
(2 users)  More options Sep 8 2006, 2:04 am
From: "Adrian Holovaty" <holov...@gmail.com>
Date: Fri, 8 Sep 2006 01:04:10 -0500
Local: Fri, Sep 8 2006 2:04 am
Subject: ANN: User-creation hole fixed in Django development (Subversion) version
Hello all,

Thanks to a report 30 minutes ago from Robert Bunting, we've fixed a
hole in the Django admin site that allows non-authenticated users to
create unprivileged user accounts by guessing a URL.

This affects people using the Django development version, revision
3520 or higher. It does *not* affect people running any official
Django release. We're making this announcement in case some people are
using the development version on a production site somewhere.

The unprivileged user accounts created do not have any permission to
do anything, including logging into the admin site, but clearly it's
still important to patch this hole.

To patch your code, just do a "svn update" of your Django code: At the
command prompt, change into your "django" directory and type "svn
update". The fix was made in revision 3736.

(Cross-posted to django-users mailing list because django-announce
doesn't have many subscribers. Please take a moment to sign up for
that list, because we won't be posting announcements to django-users
for much longer, in favor of django-announce. Sign up here:
http://groups.google.com/group/django-announce/ )

Adrian

--
Adrian Holovaty
holovaty.com | djangoproject.com


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google