blob: e977cffbab6a85604edcba9745839f83f07fc29f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
|
===========================
Django 1.8.15 release notes
===========================
*September 26, 2016*
Django 1.8.15 fixes a security issue in 1.8.14.
CSRF protection bypass on a site with Google Analytics
======================================================
An interaction between Google Analytics and Django's cookie parsing could allow
an attacker to set arbitrary cookies leading to a bypass of CSRF protection.
The parser for ``request.COOKIES`` is simplified to better match the behavior
of browsers and to mitigate this attack. ``request.COOKIES`` may now contain
cookies that are invalid according to :rfc:`6265` but are possible to set via
``document.cookie``.
|