Release | August 24, 2011

django CMS 2.1.4 security release issued

This afternoon a possible security issue in our text plugin was brought to our attention. All django CMS versions are affected, and as a result we released version 2.1.4. Thanks go to Klaas van Schelven for reporting this issue.
5 minutes read

The security issue fixed in this release allowed users with administrator accounts that have the right to edit pages to inject javascript into text plugins which could allow them to hijack user accounts with higher permission levels than themselves. As a result, no javascript is allowed in the text plugins anymore, and the 2.1.4 release contains a migration script to clean all existing plugins. The snippet plugin, which also has this flaw, continues to allow javascript and should therefore be used very cautiously.

Full list of changes in this release

  • No longer allow javascript in text plugins.
  • Clean all javascript from text plugins
  • Added html5lib as a dependency to do the javascript filtering.

Affected versions

  • all versions

Detailed upgrade instructions

Update your django CMS to 2.1.4 and run the south migration using the migrate text management command.

General note concerning security

Please report any potential security issue you discover via private email to [email protected]. Please do not report it to the github issue tracker or any of the mailing lists.

Release

django CMS 5.1.3 and 5.0.13 released

We’re pleased to announce the release of django CMS 5.1.3 and django CMS 5.0.13. Both are maintenance releases focused on fixes and improved robustness.

Community news

Inside the Work That Moves django CMS Forward

As the django CMS fellows, we have spent this year so far strengthening that foundation and making new capabilities available to developers and editors.

Tutorials

django CMS 5.1: Your CMS, Your Way — Now Easier to Set Up Than Ever

Setting up a powerful CMS shouldn’t be the hardest part of building a website. With django CMS 5.1, it no longer has to be.