Pylons

< Back to all blog entries

Paste 1.7.4 Released, Addresses XSS Security Hole

Posted by Ben Bangert on June 24, 2010

Paste 1.7.4 has been released. This update includes a fix to a XSS security hole present in the StaticURLParser and PkgResourcesParser which serve static files in Pylons.

Those using the default error controller in Pylons in their application will be affected by this if routing to the img/style action’s is still possible, or if either of these classes is used to serve static files elsewhere.

Upgrading to Paste 1.7.4 will remedy the issue.

Ian Bicking’s Paste release announcement:
http://groups.google.com/group/pylons-discuss/browse_thread/thread/3b3fff3dadd0b1e5

Comments (53)

kirth
Dec 21, 2011 8:56:44 AM

Hackers are constantly experimenting with a Lisinopril dosage wide repertoire of hacking techniques to compromise websites and web applications and make off with a treasure trove of sensitive data

You must login before you can comment.

Powered by Pylons - Contact Administrators