KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I'm maintaining a production Django 1.5 application. Recently there was a lot of noise about various vulnerabilities related to the loading of JSON, XML and YAML objects. If I understand correctly, input was carefully crafted to exploit bugs in the loading functions. Now, I have no idea where Django (or the dozens of third-party apps that we use) use each of these protocols. How can I be safe from such vulnerabilities? Do I need to make sure in some way that Django is loading JSON, XML and YAML safely?
Tags (comma-separated)
Save Edits
Cancel