Re: ANN: User-creation hole fixed in Django development (Subversion) version

2006-09-07 Thread Kenneth Gonsalves
On 08-Sep-06, at 11:34 AM, Adrian Holovaty wrote: > We're making this announcement in case some people are > using the development version on a production site somewhere. thanks for the prompt work - afaik most production sites are running on the development version -- regards kg http://l

ANN: User-creation hole fixed in Django development (Subversion) version

2006-09-07 Thread Adrian Holovaty
Hello all, Thanks to a report 30 minutes ago from Robert Bunting, we've fixed a hole in the Django admin site that allows non-authenticated users to create unprivileged user accounts by guessing a URL. This affects people using the Django development version, revision 3520 or higher. It does *no