[Python-modules-team] Bug#890097: src:django-anymail: New, minor WEBHOOK_AUTHORIZATION security issue

Salvatore Bonaccorso carnil at debian.org
Sat Mar 10 15:21:14 UTC 2018


Hi,

On Sun, Feb 11, 2018 at 01:08:01AM -0500, Scott Kitterman wrote:
> Given that the fix for this is problematic from a backward compatility
> perspective and that it requires a misconfigured django app before it is a
> problem, recommend No DSA for the security team.

Scott, sorry we did not respond earlier. Yes agree, and marked it as
no-dsa.

Regards,
Salvatore



More information about the Python-modules-team mailing list