id: PYSEC-2014-79 details: Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name. affected: - package: name: djblets ecosystem: PyPI purl: pkg:pypi/djblets ranges: - type: GIT repo: https://github.com/djblets/djblets events: - introduced: "0" - fixed: 50000d0bbb983fa8c097b588d06b64df8df483bd - fixed: 77ac64642ad530bf69e390c51fc6fdcb8914c8e7 - fixed: e2c79117efd925636acd871a5f473512602243cf - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.7.30 - introduced: "0.8" - fixed: 0.8.3 versions: - "0.5" - 0.5.1 - 0.5.2 - 0.5.3 - 0.5.4 - 0.5.5 - 0.5.6 - 0.5.7 - 0.5.8 - 0.5.9 - 0.5rc2 - "0.6" - 0.6.1 - 0.6.10 - 0.6.11 - 0.6.12 - 0.6.13 - 0.6.14 - 0.6.15 - 0.6.16 - 0.6.17 - 0.6.18 - 0.6.19 - 0.6.2 - 0.6.20 - 0.6.21 - 0.6.22 - 0.6.23 - 0.6.24 - 0.6.25 - 0.6.26 - 0.6.27 - 0.6.28 - 0.6.29 - 0.6.3 - 0.6.30 - 0.6.31 - 0.6.4 - 0.6.5 - 0.6.6 - 0.6.7 - 0.6.8 - 0.6.9 - "0.7" - 0.7.1 - 0.7.10 - 0.7.11 - 0.7.12 - 0.7.13 - 0.7.14 - 0.7.15 - 0.7.16 - 0.7.17 - 0.7.18 - 0.7.19 - 0.7.2 - 0.7.20 - 0.7.21 - 0.7.22 - 0.7.23 - 0.7.24 - 0.7.25 - 0.7.26 - 0.7.27 - 0.7.28 - 0.7.29 - 0.7.3 - 0.7.4 - 0.7.5 - 0.7.6 - 0.7.7 - 0.7.8 - 0.7.9 - "0.8" - 0.8.1 - 0.8.2 references: - type: ADVISORY url: http://secunia.com/advisories/58691 - type: FIX url: https://github.com/djblets/djblets/commit/50000d0bbb983fa8c097b588d06b64df8df483bd - type: WEB url: http://seclists.org/oss-sec/2014/q2/498 - type: WEB url: http://seclists.org/oss-sec/2014/q2/494 - type: FIX url: https://github.com/djblets/djblets/commit/77ac64642ad530bf69e390c51fc6fdcb8914c8e7 - type: FIX url: https://github.com/djblets/djblets/commit/e2c79117efd925636acd871a5f473512602243cf - type: ADVISORY url: https://github.com/advisories/GHSA-4xf6-xr96-7vmp aliases: - CVE-2014-3995 - GHSA-4xf6-xr96-7vmp modified: "2021-08-27T03:22:03.303468Z" published: "2014-06-16T18:55:00Z"