File _patchinfo of Package patchinfo.18200
<patchinfo incident="18200"> <issue tracker="cve" id="2021-46898"/> <issue tracker="bnc" id="1216481">VUL-0: CVE-2021-46898: python-django-grappelli: views/switch.py vulnerable to protocol-relative URL attacks</issue> <packager>dirkmueller</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for python-django-grappelli</summary> <description>This update for python-django-grappelli fixes the following issues: Update to 2.14.4: - CVE-2021-46898: Fixed views/switch.py vulnerable to protocol-relative URL attacks (boo#1216481) - Fixed: Redirect with switch user. - Improved: Remove extra filtering in AutocompleteLookup. - Improved: Added import statement with URLs for quickstart docs. - Improved: Added additional blocks with inlines to allow override. - Fixed: Compatibility with Django 3.1. - Fixed: Docs about adding Grappelli documentation URLS. </description> </patchinfo>