File _patchinfo of Package patchinfo

<patchinfo incident="15828">
  <issue tracker="bnc" id="1177205">VUL-0: CVE-2020-25626: python-djangorestframework: XSS Vulnerability in API viewer</issue>
  <issue tracker="cve" id="2020-25626"/>
  <packager>mcalabkova</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python-djangorestframework</summary>
  <description>This update for python-djangorestframework fixes the following issues:

Update to 3.11.2

* Security: Drop urlize_quoted_links template tag in favour of 
  Django's built-in urlize. Removes a XSS vulnerability for some 
  kinds of content in the browsable API. (boo#1177205, CVE-2020-25626)
* update Django for APIs book to 3.0 edition
* decode base64 credentials as utf8; adjust tests
* Remove compat urls for Django &lt; 2.0

This update was imported from the openSUSE:Leap:15.2:Update update project.</description>
</patchinfo>
openSUSE Build Service is sponsored by