ASA-201906-1 log generated external raw

[ASA-201906-1] python2-django: cross-site scripting
Arch Linux Security Advisory ASA-201906-1 ========================================= Severity: Medium Date : 2019-06-04 CVE-ID : CVE-2019-12308 Package : python2-django Type : cross-site scripting Remote : Yes Link : Summary ======= The package python2-django before version 1.11.21-1 is vulnerable to cross-site scripting. Resolution ========== Upgrade to 1.11.21-1. # pacman -Syu "python2-django>=1.11.21-1" The problem has been fixed upstream in version 1.11.21. Workaround ========== None. Description =========== The clickable "Current URL" link generated by AdminURLFieldWidget displayed the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link. AdminURLFieldWidget now validates the provided value using URLValidator before displaying the clickable link. You may customise the validator by passing a validator_class kwarg to AdminURLFieldWidget.__init__(), e.g. when using ModelAdmin.formfield_overrides. Impact ====== A remote attacker is able to execute javascript and create html content in the admin view. References ==========